Certified Information Security Manager (CISM)Information Security GovernanceHard

An organization is preparing for an initial public offering (IPO) and is undergoing significant scrutiny regarding its governance practices. The CISO is asked to demonstrate how information security governance is integrated into the broader enterprise governance structure. Which of the following actions BEST demonstrates this integration?

  1. AEstablishing a standalone information security department reporting directly to the CISO.
  2. BDeveloping a comprehensive set of security policies independent of other corporate policies.
  3. CEnsuring information security risks are formally included in the enterprise-wide risk management (ERM) framework.
  4. DImplementing an advanced security information and event management (SIEM) system.
Show answer & explanation

Correct answer: C. Ensuring information security risks are formally included in the enterprise-wide risk management (ERM) framework.

Integrating information security risks into the enterprise-wide risk management (ERM) framework is the most effective way to demonstrate integration into broader enterprise governance. This shows that information security is considered a fundamental business risk alongside financial, operational, and strategic risks, making it visible and manageable at the executive and board levels.

Why the other options are wrong

  • A. A standalone department is necessary but doesn't inherently demonstrate integration into the enterprise governance structure.
  • B. Developing security policies independently detracts from integration and can lead to misalignment with overall corporate objectives.
  • D. Implementing a SIEM is a technical control, not a demonstration of governance integration at the enterprise level.

InfoSec Enterprise Governance Integration

The process of embedding information security governance principles, processes, and risk management into the organization's overarching enterprise governance framework and objectives.

  • Ensures security supports business goals.
  • Elevates security to a strategic level.
  • Facilitates resource allocation and accountability.

Memory trick: Security is a pillar, not a separate room, in the enterprise house.

More Information Security Governance questions