nerdexam
Isaca

CISM · Question #897

Who is accountable for approving an information security governance framework?

The correct answer is A. Senior management. Governance accountability sits at the top of the organization. Senior management - the board of directors or executive leadership - is ultimately responsible for setting the tone for governance and approving the frameworks that govern how the organization manages risk and…

Submitted by kim_seoul· Apr 18, 2026Information Security Governance

Question

Who is accountable for approving an information security governance framework?

Options

  • ASenior management
  • BInformation security steering committee
  • CInformation security manager
  • DEnterprise risk committee

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    3% (1)
  • C
    7% (2)
  • D
    3% (1)

Explanation

Governance accountability sits at the top of the organization. Senior management - the board of directors or executive leadership - is ultimately responsible for setting the tone for governance and approving the frameworks that govern how the organization manages risk and information security. The information security steering committee (B) typically recommends and oversees implementation but is not the final approving authority. The information security manager (C) and enterprise risk committee (D) play advisory and operational roles. Approval authority for governance frameworks must rest with senior management to carry organizational weight and enforce compliance.

Topics

#Information security governance#Accountability#Senior management responsibility#Framework approval

Community Discussion

No community discussion yet for this question.

Full CISM Practice