CISM Information Security Program Practice Question
A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.
Developing a unified set of controls that satisfy the common requirements of all regulations and mapping them to each regulation's specific needs (Option A) is the best approach. This balances compliance by ensuring all regulations are addressed, efficiency by leveraging common controls, and cost reduction by avoiding duplicate efforts. Option B (adopting ISO 27001 alone) may not cover all regulatory specificities and requires additional mapping. Option C (separate programs) is inefficient and costly due to duplication. Option D (focusing on the most stringent regulation) can lead to gaps in less stringent but unique requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.
Why this is correct
A unified control framework reduces duplication, lowers costs, and simplifies compliance while covering all regulatory requirements.
- ✗
Adopt ISO 27001 as the single framework and map it loosely to all regulations.
Why it's wrong here
ISO 27001 is a good baseline but may not address all compliance nuances across 30 countries.
- ✗
Create three separate security programs, one for each major regulation (GDPR, CCPA, financial directives).
Why it's wrong here
Separate programs create duplication, increase costs, and complicate management and auditing.
- ✗
Use the most stringent regulation (e.g., GDPR) as the baseline and accept potential gaps with other regulations.
Why it's wrong here
This approach may leave the firm non-compliant with regulations that have unique requirements not covered by the strictest one.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.