mediumMultiple Choice
CISM Practice Question: A multinational corporation is establishing an…
A multinational corporation is establishing an information security governance framework. The board has approved a top-down approach where security policies are created at the corporate level and adapted locally. Which of the following is a key benefit of this approach?
⚠ Common exam trap
It's easy for candidates to confuse 'adapting locally' with 'creating locally' (Option A), failing to recognize that the key benefit of a top-down model is ensuring a consistent baseline while accommodating local legal adjustments, not delegating full policy creation to subsidiaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It ensures a consistent baseline of security controls while allowing for local regulatory adjustments.
A top-down governance approach ensures that a consistent baseline of security controls is mandated at the corporate level, which is critical for managing risk across a multinational enterprise. By allowing local adaptation, the framework can incorporate region-specific legal requirements (e.g., GDPR in Europe, CCPA in California) without deviating from the core security posture. This balance between uniformity and flexibility is the primary benefit, as it prevents fragmented security while respecting jurisdictional mandates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows each subsidiary to develop security policies that best fit their local legal environment.
Why it's wrong here
In a top-down framework, corporate policy sets the baseline and local documents adapt it; subsidiaries cannot independently author policies that diverge from it. It is tempting because local legal variation genuinely matters, but that variation is handled through adaptation of corporate policy, not autonomous policy creation.
- ✗
It reduces the time required to implement security policies across the entire organization.
Why it's wrong here
Corporate policy still needs local adaptation, translation into procedures and rollout across each subsidiary, so elapsed implementation time is not inherently shortened. It is tempting because a single approved policy avoids duplicated drafting, but the adaptation and deployment effort at each site remains.
- ✗
It minimizes the need for local security teams to understand the corporate strategy.
Why it's wrong here
A top-down framework still requires local teams to interpret corporate policy within their own regulatory and operational context; removing that understanding breaks the adaptation step. It is tempting because centralisation appears to reduce local workload, but local ownership of implementation remains essential for governance effectiveness.
- ✓
It ensures a consistent baseline of security controls while allowing for local regulatory adjustments.
Why this is correct
A corporate-level policy set enforces a uniform minimum baseline of security controls across all business units, satisfying the governance requirement for enterprise-wide consistency. Simultaneously, permitting local adaptation lets each region meet jurisdiction-specific regulatory obligations, such as GDPR or PIPEDA, without fragmenting the overarching framework. This balances standardisation with necessary legal compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.