CISM Information Security Programme Practice Question
A global manufacturer is consolidating its information security programme after several acquisitions. The CISO must establish a consistent policy framework across business units with differing local regulations. Which TWO actions are MOST important to ensure the framework is both consistent and compliant? (Choose two.)
⚠ Common exam trap
The trap here is believing that either full centralisation or full delegation solves multi-jurisdiction compliance, when the workable model is a common baseline with documented, traceable local exceptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Map the global policy framework to applicable external standards and regulations, and maintain a traceability matrix showing coverage per jurisdiction.
Consistency and compliance are achieved by pairing a mandatory global policy baseline with a governed exception path, and by mapping that baseline to applicable laws and standards through a traceability matrix. The exception process keeps local regulatory constraints visible and formally accepted, while the matrix provides audit evidence of coverage. Together they let the CISO standardise controls without ignoring jurisdictional differences.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permit each acquired business unit to retain its existing policies until the next scheduled audit cycle.
Why it's wrong here
Deferring harmonisation leaves the organisation with fragmented controls and unmanaged risk during the integration period, which is precisely when exposure is highest. Existing policies may contain gaps or conflicts that auditors will flag. CISM expects deliberate, timely convergence under a governing framework rather than passive deferral to audit timelines.
- ✗
Delegate policy ownership entirely to each regional CISO and require only annual attestation of compliance.
Why it's wrong here
Total delegation recreates the fragmentation the consolidation is meant to resolve, and annual attestation is too infrequent to detect drift or emerging regulatory change. It also weakens the group CISO's ability to set and enforce a common baseline. CISM expects central governance with local implementation, not abdication of framework ownership.
- ✓
Map the global policy framework to applicable external standards and regulations, and maintain a traceability matrix showing coverage per jurisdiction.
Why this is correct
A traceability matrix demonstrates how each policy requirement satisfies applicable laws and standards in every jurisdiction, providing evidence for auditors and regulators. It also reveals overlaps and conflicts early, so the framework can be adjusted before local assessments. This makes consistency and compliance verifiable rather than assumed, which is essential across diverse regulatory environments.
- ✓
Publish a single global security policy set with mandatory controls and allow documented local exceptions approved through a formal risk acceptance process.
Why this is correct
A single policy baseline with a governed exception process delivers consistency while acknowledging that local law, such as GDPR data localisation or works council consultation, may prevent strict adherence. Documented exceptions preserve compliance and create visibility of residual risk for the CISO. This balances standardisation with regulatory reality, which is the core governance challenge in a post-acquisition environment.
- ✗
Adopt the strictest regulation from any jurisdiction as the single global standard for all business units.
Why it's wrong here
Applying the strictest rule everywhere can impose unnecessary cost and operational burden, and may still conflict with local legal requirements such as data localisation or employee monitoring restrictions. It also assumes strictest equals most compliant, which is not guaranteed. CISM favours risk-based harmonisation with traceability, not blanket maximalism.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.