Courseiva

CISM Information Security Program Practice Question

A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?

⚠ Common exam trap

CISM often tests whether candidates choose a single framework or the most stringent regulation as a shortcut, when the best practice is a harmonized control set mapped to each regulation to avoid both gaps and duplication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.

A unified set of controls that satisfies the common requirements of all regulations and maps to each regulation's specific needs provides a single, efficient control framework while ensuring compliance with each regulation. This balances compliance, efficiency, and cost by avoiding duplication and gaps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.

    Why this is correct

    A unified control set satisfies GDPR, CCPA and financial directives simultaneously, then maps each control to individual regulatory clauses. This removes duplicated regional programmes, cutting cost and inconsistency while giving the board one auditable framework demonstrating compliance everywhere.

  • ✗

    Adopt ISO 27001 as the single framework and map it loosely to all regulations.

    Why it's wrong here

    ISO 27001 certification does not by itself satisfy GDPR, CCPA or financial directives; a loose mapping leaves region-specific obligations unenforced, so the board gains no demonstrable compliance. It is tempting because ISO 27001 provides a recognised ISMS structure, and would suit a firm needing one certifiable baseline where no prescriptive regulation applies.

  • ✗

    Create three separate security programs, one for each major regulation (GDPR, CCPA, financial directives).

    Why it's wrong here

    Three parallel programs duplicate controls, multiply audit effort and cost, and entrench the inconsistent regional enforcement the firm already struggles with. Separate programs suit wholly disjoint regulatory domains with no shared controls. A single harmonised framework mapped to each regulation satisfies all regimes at lower cost.

  • ✗

    Use the most stringent regulation (e.g., GDPR) as the baseline and accept potential gaps with other regulations.

    Why it's wrong here

    Adopting GDPR as a baseline leaves CCPA-specific obligations, such as opt-out of sale and California notice requirements, unaddressed, so gaps remain. A single baseline suits harmonising overlapping regimes, but here it cannot demonstrate compliance with divergent mandates. A unified control framework mapped to each regulation closes gaps.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.