CISM Information Security Governance Practice Question
An organization is implementing a hybrid governance model for information security. Which statement best describes this approach?
⚠ Common exam trap
CISM often tests the distinction between centralized, decentralized, and hybrid governance — candidates confuse hybrid with decentralized because both involve business units, but hybrid retains central policy-setting and oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A central security team sets policies and provides oversight, while business units execute security operations
A hybrid governance model combines central oversight with distributed execution: a central security team sets policies, standards, and provides oversight, while business units execute security operations tailored to their needs. This balances consistency with business agility. It is the defining characteristic of a federated or hybrid approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All security decisions are made by a central security team
Why it's wrong here
Centralising all security decisions contradicts hybrid governance, which distributes authority between central and business-unit levels. It is tempting because central teams set standards, but full centralisation removes the local autonomy that defines a hybrid model.
- ✗
Each business unit has full autonomy over security without central coordination
Why it's wrong here
Full autonomy for each business unit describes decentralised governance, which omits the central oversight that makes hybrid governance hybrid. It is tempting because federated models do grant units latitude over their own controls, and that works where units face genuinely distinct risks and no shared regulatory obligation. Here, though, the stem requires central coordination alongside local autonomy.
- ✗
Security is outsourced to a third-party provider
Why it's wrong here
Outsourcing security to a third party is a sourcing decision, not a governance structure. It is tempting because providers can support governance, but hybrid governance concerns how internal central and business-unit responsibilities are divided, regardless of who delivers the service.
- ✓
A central security team sets policies and provides oversight, while business units execute security operations
Why this is correct
Hybrid governance splits accountability: the central security function defines policy and monitors compliance, while business units own day-to-day execution. This matches the stem's requirement by combining enterprise-wide consistency with delegated operational control, rather than centralising all operations or leaving each unit fully autonomous.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.