Analyzing how security policies and practices are integrated into business processes (B) provides the clearest view of governance effectiveness. CISM defines governance as the alignment of security with business objectives, supported by defined roles, accountability, and decision-making structures. BIAs (A) and risk analyses (C) provide valuable inputs but do not directly assess governance maturity. Interviews (D) can supplement understanding but are subjective without observing real integration. By evaluating whether security is embedded in procurement, development, operations, and decision workflows, a new security manager can determine whether governance is formalized, consistently applied, and supported by management.
[References: ISACA CISM Review Manual (Governance—structure, integration, and effectiveness); CISM Exam Content Outline (Domain 2)., , , ]
Submit