CISM Information Security Governance Practice Question
A multinational organization must comply with GDPR, CCPA, and PCI DSS. Which approach is MOST effective for managing these overlapping requirements?
⚠ Common exam trap
CISM often tests whether candidates confuse 'prioritize the strictest regulation' with true harmonization — the trap is that the strictest regulation rarely covers all obligations, so picking C leaves compliance gaps that a mapped framework would catch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop a unified compliance framework that maps controls to multiple regulations
A unified compliance framework maps common controls to multiple regulatory requirements (GDPR, CCPA, PCI DSS), eliminating duplicated effort, reducing gaps, and providing a single source of truth for auditors. This is the standard 'compliance harmonization' or 'control mapping' approach recommended by ISACA and industry frameworks such as the Unified Compliance Framework (UCF) and NIST SP 800-53 mappings. It allows one control implementation to satisfy several regulations simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outsource compliance management to a third-party consultant
Why it's wrong here
Consultants supply expertise but no enforceable control; accountability for GDPR, CCPA and PCI DSS remains with the organisation, and overlapping obligations still need a unified control mapping. Outsourcing suits short-term gap assessments or specialist audits, not ongoing governance of intersecting regulatory requirements.
- ✓
Develop a unified compliance framework that maps controls to multiple regulations
Why this is correct
A unified framework maps common controls once and cross-references them to GDPR, CCPA and PCI DSS, eliminating duplicated evidence and conflicting interpretations. It satisfies the overlapping-requirements constraint by managing obligations through a single control set rather than separate, parallel compliance programmes.
- ✗
Prioritize compliance based on the most stringent regulation
Why it's wrong here
Prioritising the strictest regulation ignores that GDPR, CCPA and PCI DSS impose different obligations on different data; satisfying one leaves others unmet. This approach suits a single dominant regime, not reconciling overlapping requirements, which needs a unified control framework mapping each obligation.
- ✗
Assign separate teams to manage each regulation
Why it's wrong here
Separate teams per regulation duplicate controls and create conflicting interpretations across GDPR, CCPA and PCI DSS. It is tempting because dedicated ownership appears to ensure focus, but it would be correct only where regulations demand genuinely distinct, non-overlapping control sets.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.