CISM Information Security Program Practice Question
During a merger, two companies with different information security programs are being integrated. The combined entity must maintain compliance with PCI DSS and GDPR. The CISO is concerned about gaps in coverage due to differing maturity levels. Which of the following is the BEST approach to harmonize the programs?
⚠ Common exam trap
The trap is choosing the seemingly decisive option ('adopt the stricter program' or 'build a new framework') over the methodical one; CISM emphasizes risk-based, evidence-driven approaches, so gap analysis is almost always the correct answer for harmonization questions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a gap analysis against the requirements and prioritize remediation.
A gap analysis against the combined requirements of PCI DSS and GDPR identifies exactly where each legacy program falls short, allowing the CISO to prioritize remediation based on risk and regulatory obligation. This is the standard, defensible approach for harmonizing programs during M&A because it is evidence-based, accounts for differing maturity levels, and produces a prioritized roadmap rather than a blunt consolidation. It also respects that the two regulations have different scopes (PCI DSS for cardholder data, GDPR for personal data of EU residents).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adopt the more stringent security program from the acquirer across the entire entity.
Why it's wrong here
Adopting the acquirer's programme wholesale ignores the acquired company's controls that may already exceed it, and may not address PCI DSS or GDPR obligations the acquirer never faced. It is tempting because standardising on one proven programme is fast and reduces duplication. The stem's concern is coverage gaps across differing maturity levels, which requires mapping both programmes to the regulations.
- ✗
Merge the two programs by combining all controls from each.
Why it's wrong here
Combining every control from both programmes produces redundant and conflicting requirements without resolving which satisfies PCI DSS or GDPR, inflating cost and audit scope. It is tempting because unioning controls appears to guarantee no gap is missed. Harmonisation requires mapping controls to regulatory requirements and retaining one effective control per requirement, not accumulating both.
- ✗
Implement a completely new framework that meets both regulations.
Why it's wrong here
Building a new framework duplicates effort and discards existing controls that already satisfy parts of PCI DSS and GDPR, delaying compliance during integration. It is tempting because a clean-sheet design avoids inheriting either legacy programme's weaknesses. The requirement is harmonising two working programmes against known regulatory baselines, which a gap analysis and control mapping achieve directly.
- ✓
Perform a gap analysis against the requirements and prioritize remediation.
Why this is correct
A gap analysis against PCI DSS and GDPR requirements identifies where each legacy programme falls short, letting the CISO prioritise remediation by risk and compliance impact. This harmonises differing maturity levels using a common control baseline rather than adopting one company's programme wholesale.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.