CISM Information Security Governance Practice Question
A multinational corporation operates in multiple jurisdictions with varying data protection laws. The CISO is establishing a governance structure to manage compliance with these laws while maintaining a consistent security posture. Which of the following is the MOST effective approach for the CISO to take?
⚠ Common exam trap
The trap here is assuming that either a single global policy or full local delegation is sufficient, when the most effective approach combines global baseline with local flexibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop a common governance framework with baseline controls, supplemented by local addenda to address specific regulatory requirements.
The most effective approach is a common governance framework with baseline controls and local addenda. This ensures a consistent global security posture while allowing for compliance with varying local laws. It provides centralized oversight and scalability, avoiding the pitfalls of a one-size-fits-all policy or full decentralization. This hybrid model is a recognized best practice for multinational governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delegate compliance responsibility entirely to local business units to tailor security controls to each jurisdiction.
Why it's wrong here
Full delegation to local units can result in inconsistent security postures and gaps in global oversight. While local tailoring is necessary, the CISO must maintain a centralized governance framework to ensure minimum standards and accountability. Complete delegation undermines the CISO's ability to manage enterprise-wide risk.
- ✓
Develop a common governance framework with baseline controls, supplemented by local addenda to address specific regulatory requirements.
Why this is correct
This approach balances global consistency with local compliance. A common framework ensures a baseline security posture and centralized oversight, while local addenda address jurisdiction-specific laws. It is the most effective way to manage varying requirements without sacrificing enterprise-wide risk management or operational efficiency.
- ✗
Adopt the regulatory requirements of the headquarters country as the global standard for all locations.
Why it's wrong here
Applying headquarters regulations globally may not satisfy local laws and can create legal exposure. It also ignores cultural and operational differences. While it simplifies governance, it is not effective for managing compliance in multiple jurisdictions and can lead to conflicts with local regulators.
- ✗
Implement a single global security policy that meets the strictest regulatory requirements across all jurisdictions.
Why it's wrong here
A single global policy based on the strictest requirements can be overly restrictive and may not accommodate local legal nuances or business needs. It can lead to inefficiencies and resistance. While consistency is desirable, this approach may not be practical or legally sufficient in all jurisdictions, and it ignores the need for local adaptation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.