CISM Information Security Governance Practice Question
An organization has a decentralized governance model with security teams embedded in each business unit. The CISO is concerned about inconsistent security controls across the enterprise. What is the BEST recommendation to address this?
⚠ Common exam trap
CISM often tests whether candidates overcorrect to full centralization when the scenario calls for balancing enterprise consistency with local flexibility, so the trap is selecting a fully centralized model instead of a hybrid approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopt a hybrid governance model with enterprise-wide standards and local execution
A hybrid governance model combines enterprise-wide standards, policies, and oversight from the CISO with local execution by embedded security teams in each business unit. This addresses inconsistency by establishing common controls and frameworks while preserving the agility and business alignment of decentralized teams. It is the best recommendation because it directly resolves the root cause — lack of standardized controls — without sacrificing the benefits of decentralization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Adopt a hybrid governance model with enterprise-wide standards and local execution
Why this is correct
A hybrid model centralises standards, policy and oversight while letting business units execute locally, directly resolving the inconsistent-controls problem. It satisfies the stem's constraint by retaining decentralised delivery yet imposing enterprise-wide baselines, which pure decentralisation cannot achieve.
- ✗
Conduct a risk assessment to prioritize controls
Why it's wrong here
A risk assessment identifies and ranks risks but produces no enterprise-wide control baseline, so the divergence in unit controls persists. It is tempting because risk assessment correctly precedes control selection when the organisation lacks any prioritisation of threats.
- ✗
Implement a centralized security operations center (SOC) to monitor all units
Why it's wrong here
A centralised SOC standardises monitoring and detection, not the control design and policy baseline that cause the inconsistency; embedded teams would still configure controls differently. It is tempting because a SOC genuinely fits organisations needing unified incident visibility across distributed units.
- ✗
Move to a fully centralized governance model
Why it's wrong here
Full centralisation removes the embedded unit teams the governance model depends on, and the stem asks for consistency of controls, not structural redesign. It is tempting because centralisation genuinely fits organisations whose decentralised model has failed outright.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.