CISM Information Security Program Practice Question
A global financial services firm operates in 30 countries and is subject to multiple data protection regulations, including GDPR, CCPA, and various financial services directives. The firm has a centralized information security program but struggles with inconsistent enforcement across regions. The CISO is under pressure to demonstrate compliance to the board while reducing costs. The compliance team suggests creating a separate security program for each regulation, while the IT audit team recommends adopting the most stringent regulation as the baseline. The CISO must decide on a strategy that balances compliance, efficiency, and cost. What is the best approach for the CISO to take?
⚠ Common exam trap
CISM often tests whether candidates choose a single framework or the most stringent regulation as a shortcut, when the best practice is a harmonized control set mapped to each regulation to avoid both gaps and duplication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.
A unified set of controls that satisfies the common requirements of all regulations and maps to each regulation's specific needs provides a single, efficient control framework while ensuring compliance with each regulation. This balances compliance, efficiency, and cost by avoiding duplication and gaps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Develop a unified set of controls that satisfy the common requirements of all regulations and map them to each regulation's specific needs.
Why this is correct
A unified control set satisfies GDPR, CCPA and financial directives simultaneously, then maps each control to individual regulatory clauses. This removes duplicated regional programmes, cutting cost and inconsistency while giving the board one auditable framework demonstrating compliance everywhere.
- ✗
Adopt ISO 27001 as the single framework and map it loosely to all regulations.
Why it's wrong here
ISO 27001 certification does not by itself satisfy GDPR, CCPA or financial directives; a loose mapping leaves region-specific obligations unenforced, so the board gains no demonstrable compliance. It is tempting because ISO 27001 provides a recognised ISMS structure, and would suit a firm needing one certifiable baseline where no prescriptive regulation applies.
- ✗
Create three separate security programs, one for each major regulation (GDPR, CCPA, financial directives).
Why it's wrong here
Three parallel programs duplicate controls, multiply audit effort and cost, and entrench the inconsistent regional enforcement the firm already struggles with. Separate programs suit wholly disjoint regulatory domains with no shared controls. A single harmonised framework mapped to each regulation satisfies all regimes at lower cost.
- ✗
Use the most stringent regulation (e.g., GDPR) as the baseline and accept potential gaps with other regulations.
Why it's wrong here
Adopting GDPR as a baseline leaves CCPA-specific obligations, such as opt-out of sale and California notice requirements, unaddressed, so gaps remain. A single baseline suits harmonising overlapping regimes, but here it cannot demonstrate compliance with divergent mandates. A unified control framework mapped to each regulation closes gaps.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.