Courseiva
Information Security GovernancemediumMultiple ChoiceObjective-mapped

CISM Information Security Governance Practice Question

An organization has a decentralized governance model where each business unit manages its own security team. The CISO reports to the CIO. Which of the following is the GREATEST risk associated with this structure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Inconsistent enforcement of security policies across business units

In a decentralized model, inconsistent security practices across business units can lead to gaps in protection and difficulty in enforcing enterprise-wide standards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Difficulty in achieving economies of scale for security operations

    Why it's wrong here

    This is a financial efficiency issue, not the primary risk to security posture.

  • Lack of skilled security personnel in some business units

    Why it's wrong here

    While this can occur, it is a symptom of the decentralized model rather than the greatest risk; inconsistency in policy enforcement is broader.

  • Increased cost due to duplication of security tools

    Why it's wrong here

    While cost duplication is a concern, the greatest risk is inconsistent enforcement of security policies, which can leave the organization vulnerable.

  • Inconsistent enforcement of security policies across business units

    Why this is correct

    Decentralized structures often lead to varying levels of security maturity and policy adherence, creating gaps that attackers can exploit.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.