The primary role of the information security steering committee is to ensure that security policies facilitate business practices (C). CISM defines the steering committee as a governance body that aligns security direction with business objectives, resolves conflicts, and ensures executive sponsorship. Drafting policies (B) and audits (A) are operational tasks, while gap analysis (D) is an input to governance, not its primary function. Policies that hinder business processes are unlikely to be adopted or enforced effectively, making alignment the committee’s key responsibility.
[References: ISACA CISM Review Manual (Governance—steering committee roles and responsibilities); CISM Exam Content Outline (Domain 2)., , , ]
Submit