← All Study Guides

D1: Information Security Governance

CISM (ISACA) study guide

CISM D1: Information Security Governance

CISM Domain 1 (17% weight) covers enterprise governance (organizational culture; legal, regulatory and contractual requirements; organizational structures, roles and responsibilities) and information security strategy, including governance frameworks and standards and strategic planning (budgets, resources, business case). A useful habit is to approach it as a security manager rather than a security practitioner: ask which option best serves business objectives and organizational governance, even when a more technically detailed option is also offered.

Key Concepts
  • Security strategy alignment

    An information security program exists to support business objectives, not the reverse. The governance of information security guidance in ITU-T X.1054 (the ITU twin text of ISO/IEC 27014) names the alignment of information security objectives with business objectives as a thread of governance, and ISACA defines the program as measures implemented based on business requirements and risk analysis. A useful test for any governance decision is whether it advances or obstructs what the business is trying to accomplish.

  • Roles: CISO vs. steering committee vs. board

    The board (the governing body) is accountable for the organization's performance and conformance: it sets strategic direction, defines risk appetite and approves the information security strategy. Executive management allocates resources, assigns security roles and establishes the security policy. The CISO is the individual in charge of information security. Steering committees and councils (an ERM steering committee, or CIO and CISO councils in cybersecurity) provide committee-style governance, and a formal risk committee informed by subordinate councils or working groups helps ensure communication among groups such as human resources, legal, auditing and compliance.

  • Security governance frameworks

    COBIT is ISACA's framework for the governance and management of enterprise information and technology (I&T), and one of its governance system principles is that governance is distinct from management. Information security governance is one governance area within the organization's overall governance, alongside areas such as IT, quality and finance.

  • Business case development

    Security initiatives are justified in business terms through a business case: documentation of the rationale for an investment, used to decide whether to proceed and then to manage the investment through its full economic life cycle. A cost-benefit analysis adds the positive factors and subtracts the negative ones to build the business case for a risk response. Top management should ensure information security supports the entity's objectives, and security projects with significant impact are submitted to the governing body for approval.

Confusable Pairs
  • Business-aligned answer vs. most technically thorough answer

    A useful habit when several options seem plausible is to favor the one grounded in business objectives and risk. ISO/IEC 27014 (published free as ITU-T X.1054) calls for aligning information security objectives with business objectives and for top management to ensure information security supports the entity's objectives. Governance of information security should rest on risk-based decisions, and how much security is acceptable should be based on the organization's risk appetite, so the most thorough technical control is not the best choice if it goes beyond what the risk warrants.

  • Security governance vs. security management

    Governance sets direction, policy, and oversight (the "what" and "why," typically board/executive level): the governing body sets strategies and policies, monitors performance and evaluates proposals from managers. Management plans, builds, runs and monitors activities in line with that direction (the "how," typically the CISO and team). This domain is about the former.

Sources
  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]
  6. [6]
  7. [7]
  8. [8]
  9. [9]
  10. [10]
  11. [11]
  12. [12]
  13. [13]
  14. [14]
  15. [15]
  16. [16]
  17. [17]

Practice D1 questions with instant feedback, free to start, no card required.

Start Free
Your cookie choices
We use essential cookies to run this site, and, only with your consent, advertising cookies from Google, LinkedIn, and Reddit to measure ad performance. See our for details.