Courseiva

CISM Information Security Program Practice Question

A large financial institution is updating its information security program to align with a new regulatory framework. The program currently has a decentralized governance model. Which of the following is the MOST significant risk of maintaining a decentralized model?

⚠ Common exam trap

CISM often tests governance models, and candidates may choose 'duplication of controls' or 'higher cost' as the most significant risk, overlooking that inconsistent security levels directly increase the likelihood of breaches and regulatory non-compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inconsistent security levels across business units

In a decentralized governance model, each business unit may implement its own security controls, leading to inconsistent security levels across the organization. This is the most significant risk because it creates gaps and vulnerabilities that can be exploited, especially in a regulated financial institution. While other risks exist, inconsistency directly undermines the overall security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Slower incident response

    Why it's wrong here

    Decentralised governance does slow incident response, but the regulatory driver makes inconsistent control interpretation and reporting the greater exposure. Slower response is an operational symptom; fragmented accountability across business units is what undermines demonstrable compliance.

  • ✓

    Inconsistent security levels across business units

    Why this is correct

    Decentralised governance lets each business unit set its own controls, so enforcement, risk tolerance and reporting diverge across the institution. That inconsistency directly undermines the uniform, auditable control baseline the new regulatory framework demands, creating gaps regulators can cite. Centralised models instead impose one standard, which is why this is the most significant risk.

  • ✗

    Higher cost of compliance

    Why it's wrong here

    Decentralised governance does not inherently raise compliance cost; the same regulatory obligations apply regardless of structure, so spend is not the axis of risk. It tempts because duplicated tooling and fragmented audits can inflate budgets in sprawling multinational groups, making cost a visible symptom. The stem's real exposure is inconsistent control application across business units.

  • ✗

    Duplication of controls

    Why it's wrong here

    Duplication of controls wastes effort but remains visible and locally correctable, so it rarely threatens regulatory alignment across the institution. Decentralised governance is genuinely useful in federated or subsidiary structures where business units need autonomy. Here, however, the framework demands enterprise-wide consistency, which decentralisation cannot deliver because each unit sets its own risk appetite and reporting lines.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.