hardMultiple Select
Challenges in Decentralized Information Security Governance
Which THREE of the following are challenges in implementing information security governance in a decentralized organization?
Quick Answer
The answer is inconsistent policy enforcement across business units, redundant security controls, and diverse regulatory compliance. These three challenges arise because decentralized organizations distribute authority to individual business units, which often develop their own security practices without a unifying framework, leading to gaps in policy adherence, duplicated or conflicting tools, and fragmented compliance with laws like GDPR or SOX. On the Certified Information Security Manager CISM exam, this question tests your understanding of governance structures and the pitfalls of autonomy without central oversight—a common trap is mistaking centralized incident response as a challenge when it is actually a missing solution, not a problem itself. Remember that decentralized governance struggles with consistency, efficiency, and regulatory alignment, while unified risk reporting remains an aspirational goal. A useful memory tip is to think of the three C’s: Consistency, Cost (redundancy), and Compliance—all of which suffer when security governance is spread too thin.
⚠ Common exam trap
Many exam-takers confuse the desired outcomes of governance (like unified reporting and centralized response) with the inherent challenges of a decentralized structure, leading them to select those as challenges rather than recognizing them as missing capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redundant security controls and tools
In a decentralized organization, business units often procure and operate their own security tooling, which leads to redundant security controls and tools (B) that increase cost and complexity while creating gaps and overlaps in coverage. Diverse regulatory compliance requirements (D) are a challenge because different units may operate in different jurisdictions or industries, each subject to distinct laws and standards (e.g., GDPR, HIPAA, PCI DSS), making a single governance framework difficult to apply uniformly. Inconsistent policy enforcement across business units (E) is also a core challenge, since decentralized authority means each unit may interpret, adopt, or ignore enterprise security policies differently, undermining consistent risk management. By contrast, unified risk reporting (A) and centralized incident response (C) are goals or benefits that governance seeks to achieve, not inherent challenges of decentralization; in fact, decentralization makes achieving them difficult, but they are not themselves the challenges listed as correct answers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unified risk reporting
Why it's wrong here
Unified risk reporting is a desired governance outcome that aggregates risk across units, not an obstacle to implementing governance. It would be correct if the question asked which capability decentralisation makes difficult to achieve, rather than which challenges arise.
- ✓
Redundant security controls and tools
Why this is correct
Decentralised business units independently procure and deploy security tooling, producing duplicated controls and overlapping technologies. This redundancy wastes budget and complicates governance, directly illustrating a structural challenge of implementing information security governance where authority is dispersed rather than centralised.
- ✗
Centralized incident response
Why it's wrong here
Centralised incident response is a governance strength, giving consistent handling across business units, not a challenge. It would be the answer if the question asked which controls help unify a decentralised organisation rather than which impede governance.
- ✓
Diverse regulatory compliance requirements
Why this is correct
Decentralised units operate under different national and sectoral regulations, so a single governance framework must reconcile conflicting compliance obligations. This divergence fragments policy enforcement and reporting, directly illustrating a challenge of implementing information security governance across a dispersed organisation.
- ✓
Inconsistent policy enforcement across business units
Why this is correct
Decentralised structures let each business unit interpret and apply security policy independently, so enforcement diverges. This fragmentation is a core governance challenge because no central authority can guarantee consistent control application across all units, directly matching the stem's decentralisation constraint.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?
easy- A.Merge all teams into one central unit
- B.Implement a top-down mandate for all policies
- ✓ C.Create a governance committee with representatives from each facility
- D.Outsource security to a third party
Why C: A governance committee with representatives from each facility establishes a federated governance model that aligns security practices across the hospital chain without restructuring teams. This approach enables consistent policy development, shared oversight, and coordination of patient data protection efforts while minimizing operational disruption, as each facility retains its existing team structure. It directly addresses the lack of central coordination and duplicate efforts by creating a collaborative decision-making body, which is a core principle of information security governance.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.