Courseiva

CISM Information Security Programme Practice Question

A global manufacturer is consolidating 14 regional security policies into a single enterprise information security policy set. Regional legal counsel warns that several jurisdictions impose requirements stricter than the current baseline. Which approach BEST balances consistency with legal obligations?

⚠ Common exam trap

The trap here is treating policy consolidation as an all-or-nothing choice, ignoring that regional exceptions can strengthen a global baseline without fragmenting it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a global baseline policy with documented regional exceptions that only add or strengthen requirements.

The right balance is a mandatory global baseline plus a governed exception process for regions whose laws are stricter. This delivers consistent minimum protection and comparable metrics across the enterprise while allowing lawful local strengthening. Wholesale adoption of the strictest rule, full regional autonomy, and culture-based variation each sacrifice either efficiency, legal compliance, or enterprise visibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Publish one global policy at the strictest regional requirement and retire all local variants.

    Why it's wrong here

    Adopting the strictest requirement globally is defensible for consistency but can impose unnecessary cost and operational burden in jurisdictions where it is not required, and it may conflict with local labour or privacy law constraints. It also removes the flexibility needed when a new stricter regulation appears in only one region.

  • ✗

    Keep all 14 regional policies independent and let each regional security officer maintain their own set.

    Why it's wrong here

    Retaining fully independent regional policies perpetuates fragmentation, inconsistent control expectations, and duplicated effort. It also makes enterprise-level assurance and reporting impossible, because there is no common baseline against which to measure compliance or aggregate risk across the manufacturing footprint.

  • ✓

    Establish a global baseline policy with documented regional exceptions that only add or strengthen requirements.

    Why this is correct

    A global baseline provides consistent minimum expectations and a common measurement framework, while controlled regional exceptions let jurisdictions layer on stricter legal requirements without weakening the baseline. This preserves enterprise assurance and reporting while respecting local law, and the exception register keeps deviations visible and governed.

  • ✗

    Allow each region to choose whichever policy set best fits its culture and report compliance only when audited.

    Why it's wrong here

    Cultural fit is not a legitimate basis for varying security requirements, and audit-only reporting leaves leadership blind to risk between audits. This approach guarantees inconsistent protection across regions and undermines the CISO's ability to assert that the enterprise meets a known standard, which is precisely the problem consolidation is meant to solve.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.