Courseiva

CISM Information Security Programme Practice Question

A global retailer operates in 15 countries, each with distinct data protection regulations. The CISO must design the information security programme's policy framework so that local legal requirements are met while maintaining a consistent global baseline. Which approach BEST achieves this objective?

⚠ Common exam trap

The trap here is believing that applying the single strictest standard everywhere automatically solves multi-jurisdiction compliance, when local laws can actually prohibit or conflict with such uniform practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a global baseline policy framework with mandatory enterprise controls, supplemented by local addenda that address jurisdiction-specific legal requirements.

The most effective approach combines a consistent global baseline of mandatory controls with localized addenda for jurisdiction-specific legal requirements. This preserves enterprise-wide governance and reporting while ensuring each country meets its own regulatory obligations. Fully uniform strictness, complete decentralization, and revenue-based selection each fail to balance compliance, consistency, and operational practicality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establish a global baseline policy framework with mandatory enterprise controls, supplemented by local addenda that address jurisdiction-specific legal requirements.

    Why this is correct

    A baseline-plus-local-addenda structure gives the organization a consistent, auditable core while allowing each country to layer on specific legal obligations. This preserves global control consistency, simplifies enterprise reporting, and demonstrates due diligence to regulators in each jurisdiction. It also avoids both the overreach of one-size-fits-all strictness and the fragmentation of fully independent local programmes, making it the most balanced governance approach.

  • ✗

    Allow each country's security team to develop its own independent policies tailored to local law, with no central requirements.

    Why it's wrong here

    Fully decentralized policy development creates inconsistent control environments, complicates global risk reporting, and makes enterprise-wide assurance nearly impossible. It also allows gaps to emerge where local teams lack expertise or resources. While local law is respected, the absence of a central baseline undermines the CISO's ability to demonstrate a coherent programme and increases the chance of duplicated or conflicting controls.

  • ✗

    Create a single global policy set that mandates the strictest requirement found in any jurisdiction and apply it uniformly everywhere.

    Why it's wrong here

    Applying the strictest requirement globally can satisfy compliance but often imposes unnecessary operational burden and cost in jurisdictions with lighter rules, and it may conflict with local laws that prohibit certain data handling practices. Uniform strictness also ignores legitimate local variations such as works council consultation requirements. It is a blunt instrument that meets the letter of regulation while creating friction and potential legal conflicts.

  • ✗

    Adopt the policy framework of the country with the largest revenue contribution and require all other locations to follow it.

    Why it's wrong here

    Choosing a framework based on revenue rather than legal obligation risks noncompliance in other jurisdictions whose laws differ materially. The largest market's rules may be less stringent than elsewhere, leaving the organization exposed to regulatory penalties. This approach substitutes commercial convenience for legal analysis and fails to address the scenario's core requirement of meeting distinct local data protection regulations.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.