Courseiva

CISM Information Security Program Practice Question

A multinational corporation's information security program is decentralized, with each business unit managing its own security controls. The CISO wants to implement a federated governance model to improve consistency while respecting business unit autonomy. Which of the following is the MOST critical factor for the success of this model?

⚠ Common exam trap

The trap here is equating federated governance with centralization or compliance mandates, rather than focusing on decision rights and accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defining clear roles, responsibilities, and decision rights between central and business unit security teams.

A federated governance model balances central oversight with business unit autonomy. The most critical factor is defining clear roles, responsibilities, and decision rights, which prevents confusion and ensures consistent application of security policies while allowing local flexibility. Other options focus on technology, compliance, or centralization, which do not address the core governance challenge. Without clear decision rights, federated models often stall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requiring each business unit to achieve ISO/IEC 27001 certification within one year.

    Why it's wrong here

    Mandating ISO/IEC 27001 certification is a compliance-driven approach that may not align with a federated model's emphasis on autonomy and shared responsibility. It could be costly and time-consuming, and certification does not guarantee effective governance. The success of federated governance depends on collaborative decision-making and clear accountability, not on a specific certification.

  • ✗

    Establishing a central security operations center (SOC) that monitors all business units.

    Why it's wrong here

    A central SOC can improve detection and response, but it is not the most critical factor for a federated governance model. Federated governance relies on agreed-upon policies, standards, and decision-making processes across units. A central SOC may actually conflict with autonomy if not carefully integrated. The success of federation depends more on governance structures and consensus-building than on a centralized monitoring capability.

  • ✗

    Implementing a single security toolset across all business units to ensure uniformity.

    Why it's wrong here

    A single toolset can simplify management, but it may not fit the diverse needs of business units and can undermine autonomy. Federated governance allows for local adaptation within a common framework. Mandating one toolset is more characteristic of a centralized model and could face resistance. The critical success factor is not the technology but the governance processes and relationships.

  • ✓

    Defining clear roles, responsibilities, and decision rights between central and business unit security teams.

    Why this is correct

    In a federated governance model, clear roles, responsibilities, and decision rights are essential to avoid confusion, duplication, and conflict. This ensures that central and business unit teams understand who decides what, how policies are set, and how exceptions are handled. Without this clarity, federated models often fail due to ambiguity and turf battles. It is the most critical factor because it provides the framework for consistent yet flexible security management.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.