Courseiva
hardMultiple Choice

CISM Practice Question: Acme Corp, a global manufacturer, has a…

Acme Corp, a global manufacturer, has a decentralized security governance model. Each business unit manages its own security, resulting in inconsistent policies and repeated audit findings. The new CISO proposes a federated model where a central team sets minimum standards and each unit can add local controls. However, the European unit's head insists on full autonomy due to GDPR strictness. The board is concerned about compliance costs. What should the CISO do first?

⚠ Common exam trap

The trap is that candidates may jump to a technical or immediate solution (like hiring an expert or implementing the model) without recognizing that CISM questions prioritize risk-based decision-making and assessment before action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a risk assessment to identify where local controls are truly needed

The CISO should first conduct a risk assessment to identify where local controls are truly needed, because this provides data-driven justification for the federated model and addresses the European unit's GDPR concerns. A risk assessment will reveal which business units face different regulatory or threat landscapes, allowing the CISO to tailor the federated model and demonstrate that local autonomy is only necessary where risks justify it. This approach also helps the board understand compliance costs and trade-offs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement the federated model immediately and require all units to comply

    Why it's wrong here

    Imposing the federated model immediately ignores the European unit's GDPR objection and the board's cost concern, so it fails to secure stakeholder agreement before rollout. It is tempting because federated governance does resolve inconsistent policies, but that outcome requires consensus-building first, which the question asks the CISO to do.

  • ✗

    Allow the European unit to keep full autonomy while others follow the model

    Why it's wrong here

    Granting full autonomy to the European unit preserves the decentralised inconsistency and repeated audit findings the CISO must fix, and GDPR does not require abandoning central minimum standards. It is tempting because GDPR permits local controls, but federated governance already accommodates those as additions above the baseline.

  • ✓

    Conduct a risk assessment to identify where local controls are truly needed

    Why this is correct

    A risk assessment identifies which business units genuinely require local controls, giving the CISO evidence to negotiate with the European unit and reassure the board on cost. It satisfies the stem's federated-model constraint by basing the minimum-standard boundary on actual risk rather than assumed autonomy.

  • ✗

    Hire a GDPR expert for the European unit

    Why it's wrong here

    Hiring a GDPR expert addresses regulatory interpretation but leaves the governance disagreement and audit findings unresolved, so it does not move the federated model forward. It is tempting because GDPR expertise supports the European unit's position, but the CISO's first step is aligning stakeholders on governance, not procuring specialist advice.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.