MTC Group
← All Study Guides

D1: Information Security Governance

CISM (ISACA) study guide

CISM Domain 1 (17% weight) tests whether a candidate can think like a security manager, not a security practitioner: the exam consistently rewards the answer that best serves business objectives and organizational governance, even when a more technically "correct" answer is also offered. This is the single biggest adjustment CISSP holders need to make when moving to CISM: management judgment outranks technical precision.

Key Concepts
  • Security strategy alignment

    An information security program exists to support business objectives, not the reverse. Every governance question implicitly asks whether a decision advances or obstructs what the business is trying to accomplish.

  • Roles: CISO vs. steering committee vs. board

    The CISO develops and executes strategy; a security steering committee (cross-functional business leaders) provides oversight and prioritization input; the board holds ultimate accountability for enterprise risk, including security risk.

  • Security governance frameworks

    COBIT is the dominant governance framework referenced on the CISM exam. Know that COBIT is about the overall governance and management of enterprise IT, with security governance as one component within it.

  • Business case development

    Security initiatives need to be justified in business terms (cost-benefit, risk reduction, regulatory necessity) to secure executive sponsorship and budget. A recurring exam theme is what should be included when presenting a security initiative to the board.

Confusable Pairs
  • "Most important" vs. "most immediate" answer choices

    CISM loves offering an answer that's technically correct but not the best governance answer. When multiple options seem plausible, favor whichever best serves business alignment and risk-based prioritization over the most technically thorough option.

  • Security governance vs. security management

    Governance sets direction, policy, and oversight (the "what" and "why," typically board/executive level). Management executes against that direction operationally (the "how," typically the CISO and team). CISM Domain 1 is squarely about the former.

Practice D1 questions with instant feedback, free to start, no card required.

Start Free