CISA Governance and Management of IT Practice Question
A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?
⚠ Common exam trap
The trap is choosing extreme options (full centralization or full autonomy) when the scenario explicitly demands a balance between global risk control and local flexibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopt a federated governance model with global policies and local flexibility within defined tolerances.
A federated governance model with global policies and local flexibility within defined tolerances is the most appropriate because it balances the board's mandate for stronger, centralized governance with the regional directors' need for autonomy to meet local regulations and business requirements. It establishes global minimum standards while allowing regions to adapt within approved boundaries, directly addressing the risk of weak regional controls without eliminating necessary flexibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adopt a federated governance model with global policies and local flexibility within defined tolerances.
Why this is correct
A federated model sets mandatory global policies, such as security baselines, while permitting regional deviations within defined tolerances. This directly addresses the breach caused by weak local controls without stripping the autonomy regional directors require for local regulations.
- ✗
Allow each region to continue independently but require quarterly reporting to the committee.
Why it's wrong here
Quarterly reporting gives the committee visibility after the fact without changing regional control design, so the weak controls that enabled the breach remain in place. It is tempting because reporting is a low-friction governance mechanism, and would suffice where regions already meet a common baseline, but it provides no enforcement capability.
- ✗
Implement a fully centralized IT governance model with no regional deviations.
Why it's wrong here
A fully centralised model with no regional deviation conflicts with local regulatory obligations and business requirements, which the committee must accommodate. It is tempting because centralisation directly answers the board's demand for stronger governance, and would be correct where no jurisdictional or operational variation exists, but here it creates compliance failures in regulated regions.
- ✗
Maintain the status quo but enforce minimum security standards across all regions.
Why it's wrong here
Enforcing only minimum standards leaves each region's governance, risk ownership and control design unchanged, so the weak-control gap that caused the breach persists. It is tempting because minimum baselines are a recognised way to raise the floor without centralising, and would suit a low-risk federated organisation rather than one under a board mandate after a material breach.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.