Courseiva

CISM Information Security Program Practice Question

A company is designing its information security program and wants to ensure that it meets regulatory requirements across multiple jurisdictions. Which of the following approaches is most appropriate?

⚠ Common exam trap

A common mistake in CISM is assuming that adopting a single, comprehensive standard like ISO 27001 is sufficient for multi-jurisdictional compliance, when in reality it must be supplemented with a mapping framework to address specific legal requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a regulatory compliance framework that maps controls to applicable laws and standards.

A regulatory compliance framework that maps controls to applicable laws and standards provides a structured, auditable method to address multiple, sometimes conflicting, jurisdictional requirements. This approach ensures that each control is explicitly linked to a specific legal or regulatory obligation, facilitating compliance verification and reducing the risk of oversight. It is the most comprehensive and adaptable method for a multi-jurisdictional environment, as it allows the organization to manage overlapping and unique requirements without relying on a single standard or external review alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adopt ISO 27001 as the sole framework for the program.

    Why it's wrong here

    ISO 27001 certifies a management system, not conformity with each jurisdiction's statutes; it maps to few legal obligations directly. It is tempting because it is a recognised international standard providing a structured control framework. A harmonised baseline plus jurisdiction-specific legal mapping is correct when multiple regulatory regimes apply.

  • ✓

    Implement a regulatory compliance framework that maps controls to applicable laws and standards.

    Why this is correct

    A mapped framework consolidates overlapping obligations into one control set, letting the programme satisfy multiple jurisdictions without duplicated effort. This directly addresses the cross-jurisdiction regulatory requirement by tracing each control to the specific laws and standards that mandate it.

  • ✗

    Comply with the strictest regulation and ignore others.

    Why it's wrong here

    Applying only the strictest regulation leaves obligations unique to other jurisdictions unmet, such as differing breach-notification timelines or data-residency rules. It appeals as a single, conservative benchmark. Mapping each jurisdiction's requirements and satisfying all applicable ones is correct; strictness does not imply coverage of distinct legal duties.

  • ✗

    Engage external legal counsel to review policies quarterly.

    Why it's wrong here

    Quarterly legal review of policies does not itself establish controls meeting each jurisdiction's regulatory requirements, and it lags behind regulatory change. It is tempting because legal expertise interprets obligations. A control framework mapped to each jurisdiction's legislation is correct; counsel advises on interpretation rather than implementing the security programme.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.