CISM Information Security Governance Practice Question
Which governance model is characterized by a single, centralized security team that serves the entire organization?
⚠ Common exam trap
The trap is that candidates conflate 'centralized' with 'strong' or 'best' governance, or confuse federated (coordinated but distributed) with centralized — the exam expects you to match the definition of a single team serving the whole organization precisely to the centralized model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centralized
A centralized governance model is defined by a single security team that owns and delivers security services, policy, and oversight for the entire organization. Decision-making authority, budget, and standards flow from one point, which produces consistency and clear accountability. Federated, decentralized, and hybrid models distribute authority or embed security into business units, so they do not match the single-team description.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Centralized
Why this is correct
A centralized model places all security decision-making and resources under one team, directly satisfying the stem's requirement for a single, organisation-wide authority. This structure enables consistent policy enforcement and unified accountability, unlike federated or hybrid models that distribute control across business units.
- ✗
Federated
Why it's wrong here
Federated governance distributes security responsibilities across business units or regions, each with its own team, coordinated through shared standards. A single centralised team defines the Centralised model instead. Federated is tempting where organisations span diverse regulatory jurisdictions, since local autonomy aids compliance, but it contradicts the single-team requirement.
- ✗
Decentralized
Why it's wrong here
In decentralized model, security is embedded within business units, not centralized.
- ✗
Hybrid
Why it's wrong here
Hybrid governance blends centralised and decentralised elements, so some functions report centrally while others sit within business units. A single centralised team serving the whole organisation describes the Centralised model. Hybrid tempts large enterprises balancing global policy with local responsiveness, but its split structure fails the single-team criterion.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.