Courseiva

CISM Information Security Governance Practice Question

An organization is deciding whether to adopt a centralized or hybrid security governance model. Which factor MOST strongly favors a hybrid model?

⚠ Common exam trap

CISM often tests the trade-off between centralization (uniformity, cost efficiency) and decentralization (autonomy, local fit) — candidates may pick 'uniform security' as a reason for hybrid, but uniformity is the argument for centralization, while autonomy with diverse needs is the argument for hybrid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High degree of autonomy needed by business units with diverse needs

A hybrid security governance model combines centralized standards and oversight with decentralized execution, making it most appropriate when business units need a high degree of autonomy to address diverse needs (e.g., different regulatory regimes, customer segments, or technology stacks). The hybrid model lets the center set baseline policies and risk appetite while allowing units to tailor controls to their specific contexts. This balance is the strongest argument for adopting hybrid over fully centralized or fully decentralized models.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    High degree of autonomy needed by business units with diverse needs

    Why this is correct

    A hybrid model distributes decision rights, letting central governance set baseline policy while business units retain autonomy over their own controls. This satisfies the stem's constraint directly: diverse units needing high autonomy cannot be governed effectively by a single centralised authority.

  • ✗

    Minimal security budget

    Why it's wrong here

    A minimal budget argues against hybrid, because duplicated governance functions across units cost more than one central team. It is tempting because cost pressure feels like a reason to distribute control, and would be correct if units already possessed funded security resources to absorb the work.

  • ✗

    Low regulatory requirements

    Why it's wrong here

    Low regulatory requirements do not favour hybrid governance; hybrid complexity is justified by divergent jurisdictional mandates, subsidiary autonomy or legacy system constraints, not regulatory leniency. It tempts because lighter compliance burdens genuinely permit decentralised decision-making in small, single-market firms, where a hybrid model's duplicated oversight would add cost without addressing any real governance gap.

  • ✗

    Uniform security across all business units

    Why it's wrong here

    Uniform security across all business units is the outcome centralisation delivers, since one authority sets one standard; hybrid exists precisely to permit local variation. It is tempting because consistency sounds desirable, and would be correct if the organisation had no unit-specific regulatory or operational differences.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.