Courseiva

CISM Information Security Programme Practice Question

A CISO is designing the security programme's organisational structure for a multinational manufacturer. The CISO wants to ensure the structure supports both central governance and responsiveness to regional regulatory requirements. Which TWO structural elements BEST support these goals? (Choose two.)

⚠ Common exam trap

The trap here is treating local responsiveness as requiring local autonomy, when it is better delivered through regional roles inside a centrally governed structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A central security governance function that sets policy, standards and the risk assessment methodology used worldwide.

A federated model works best here: central governance sets consistent policy, standards and methodology, while regional security officers within the security reporting line adapt implementation to local regulation and feed requirements back. This balances enterprise consistency with local responsiveness. Full delegation, complete outsourcing or fully independent country teams each break either central accountability or local regulatory fit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outsourcing the entire security function to a managed security service provider so that regional staffing costs are eliminated.

    Why it's wrong here

    Outsourcing can deliver monitoring and specialist capability, but accountability for risk and regulatory compliance cannot be transferred to a provider. Eliminating internal security staffing would also remove the local knowledge needed to interpret regional requirements, and the organisation would still be answerable to regulators for any failure.

  • ✗

    Delegating all security decision-making to regional business unit leaders so that each can respond quickly to local market conditions.

    Why it's wrong here

    Full delegation without central oversight fragments the programme, produces inconsistent risk treatment and weakens the CISO's ability to give the board a single view of enterprise risk. Local agility is valuable, but it must operate inside centrally defined policy and standards rather than replacing them.

  • ✗

    Creating a separate security team in every country, each reporting to that country's general manager with no common standards.

    Why it's wrong here

    Independent country teams reporting only to local management produce duplicated effort, incompatible controls and no enterprise-wide risk picture. Without common standards the organisation cannot demonstrate consistent control to regulators or customers, and the CISO loses the visibility needed to manage risk at the corporate level.

  • ✓

    A central security governance function that sets policy, standards and the risk assessment methodology used worldwide.

    Why this is correct

    A central governance function establishes consistent policy, standards and methodology, which is what allows the programme to be managed as one coherent effort. It gives executive management a single point of accountability and prevents each region from inventing incompatible approaches, while still leaving room for regional implementation detail.

  • ✓

    Regional security officers who report into the central security function and adapt implementation to local legal and regulatory obligations.

    Why this is correct

    Regional officers embedded in the security reporting line translate central requirements into local practice and feed regional legal obligations back into policy. This preserves the CISO's accountability while ensuring that local regulatory nuances, such as differing breach notification rules, are handled by people close to the operation rather than missed by a distant central team.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.