CISM Information Security Program Practice Question
A multinational corporation has a decentralized information security program. Each business unit has its own security team and budget. The CISO wants to improve consistency and reduce duplication of efforts. Which of the following is the MOST effective approach?
⚠ Common exam trap
The trap here is thinking that centralizing all security functions or mandating identical tools is the only way to achieve consistency, ignoring the need for business alignment and flexibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a security governance framework with common policies, standards, and a steering committee.
Establishing a security governance framework with common policies, standards, and a steering committee is the most effective approach. It provides centralized direction while allowing business units to adapt to local needs, reducing duplication and improving consistency. This balances control with flexibility, which is essential for a multinational organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outsource all security operations to a managed security service provider (MSSP).
Why it's wrong here
Outsourcing can improve efficiency but does not inherently solve consistency and duplication issues across business units. It may also introduce new risks and challenges in coordination. The CISO should first establish governance to ensure that outsourcing, if used, aligns with the overall security strategy.
- ✗
Centralize all security functions under the CISO to ensure uniform control.
Why it's wrong here
Full centralization may not be feasible or desirable in a multinational with diverse business units. It can be costly and may not respect local regulations or business needs. The goal is to improve consistency and reduce duplication while allowing flexibility, so a hybrid approach is often more effective.
- ✗
Mandate that each business unit follows the same security tools and technologies.
Why it's wrong here
Mandating identical tools may not be practical due to varying business requirements, existing investments, and regulatory differences. It can lead to resistance and inefficiency. The focus should be on standardizing processes and outcomes, not necessarily the specific technologies used.
- ✓
Establish a security governance framework with common policies, standards, and a steering committee.
Why this is correct
A governance framework with common policies and a steering committee enables consistency and coordination while respecting business unit autonomy. It provides a structure for decision-making, aligns security with business objectives, and reduces duplication by sharing best practices and resources. This approach is a hallmark of mature security programs.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.