Certified Information Security Manager (CISM)Information Security GovernanceEasy

A CISO is tasked with establishing an information security steering committee. To ensure the committee is effective and has sufficient authority, which of the following stakeholders is MOST crucial to include as a member?

  1. AA senior executive with decision-making authority for business strategy.
  2. BA junior IT auditor.
  3. CA third-party security vendor representative.
  4. DA representative from the Help Desk.
Show answer & explanation

Correct answer: A. A senior executive with decision-making authority for business strategy.

A senior executive with business strategy decision-making authority is crucial for an information security steering committee. Their presence ensures that security initiatives are aligned with business objectives, receive necessary resources, and have the organizational support required for effective governance.

Why the other options are wrong

  • B. A junior IT auditor provides compliance perspective but not strategic direction or executive influence.
  • C. A third-party vendor may offer technical expertise but should not hold a core decision-making role in internal governance.
  • D. Help Desk provides valuable operational insight but typically lacks strategic decision-making authority.

InfoSec Steering Committee Composition

The selection of key stakeholders for an information security steering committee to ensure effective governance, strategic alignment, and resource allocation.

  • Requires executive sponsorship.
  • Should include representatives from various business units.
  • Provides strategic direction and oversight for security.

Memory trick: The captain must be on the ship's steering committee.

More Information Security Governance questions