StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 1: Information security governance

Organizational structures, roles and responsibilities (board, steering committee, CISO, data owners)

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Security works only when people know who decides, who does the work and who checks it. CISM expects you to know the standard roles and where accountability sits. The board of directors sets overall direction and risk appetite and oversees management; it is ultimately accountable for protecting the organization's assets. Executive management, led by the chief executive officer (CEO), turns that direction into strategy, funds it and makes sure the organization carries it out. Board committees, such as an audit committee or a risk committee, often receive security reports on the board's behalf.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan