Courseiva

CISM Information Security Program Practice Question

A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget, and they report to their respective business unit leaders. The CISO has limited authority over these teams. A recent incident revealed inconsistent security controls across business units, and the board is concerned about the overall risk posture. Which of the following should the CISO recommend to improve the program's effectiveness?

⚠ Common exam trap

The trap here is thinking that only full centralization or outsourcing can solve inconsistency, when a federated model often better fits a decentralized organization with limited CISO authority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a federated security model with a central governance framework and common standards, while allowing business units to implement controls tailored to their specific risks.

A federated security model with central governance and common standards addresses the inconsistency while respecting the decentralized structure. It allows the CISO to set minimum requirements and oversight without stripping business units of their autonomy. This approach is practical given the CISO's limited authority and the need for tailored controls based on specific business unit risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a security awareness program across all business units to improve adherence to policies.

    Why it's wrong here

    Security awareness is important, but the issue is inconsistent controls, not lack of awareness. The business units may have their own security teams that are aware of policies but are not implementing them consistently due to lack of central oversight. Awareness training alone would not resolve the structural governance problem. A governance framework is needed to ensure consistent control implementation.

  • ✗

    Outsource all security operations to a managed security service provider (MSSP) to achieve uniform controls.

    Why it's wrong here

    Outsourcing can provide consistent controls, but it may not align with the organization's risk appetite or regulatory requirements. It also reduces internal control and may be more expensive. The scenario does not indicate that the business units lack resources; rather, the issue is inconsistency due to decentralization. An MSSP might not understand the specific risks of each business unit, so it is not the best first step.

  • ✗

    Centralize all security functions under the CISO to ensure consistent implementation of controls.

    Why it's wrong here

    While centralization can improve consistency, it may not be feasible or desirable in a multinational corporation with diverse business units. It could also create resistance and slow down business operations. The CISO's limited authority suggests that a full centralization might not be politically viable. A more balanced approach that establishes common standards while allowing some flexibility is often more effective in decentralized organizations.

  • ✓

    Establish a federated security model with a central governance framework and common standards, while allowing business units to implement controls tailored to their specific risks.

    Why this is correct

    A federated model balances central governance with local implementation. It provides consistent standards and oversight through a central framework, while enabling business units to adapt controls to their unique risks and regulatory requirements. This approach addresses the inconsistency issue without alienating business units, and it works within the CISO's limited authority by using influence and collaboration rather than direct control.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.