Courseiva

CISM Information Security Governance Practice Question

Which governance model is characterized by a single, centralized security team that serves the entire organization?

⚠ Common exam trap

The trap is that candidates conflate 'centralized' with 'strong' or 'best' governance, or confuse federated (coordinated but distributed) with centralized — the exam expects you to match the definition of a single team serving the whole organization precisely to the centralized model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centralized

A centralized governance model is defined by a single security team that owns and delivers security services, policy, and oversight for the entire organization. Decision-making authority, budget, and standards flow from one point, which produces consistency and clear accountability. Federated, decentralized, and hybrid models distribute authority or embed security into business units, so they do not match the single-team description.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Centralized

    Why this is correct

    A centralized model places all security decision-making and resources under one team, directly satisfying the stem's requirement for a single, organisation-wide authority. This structure enables consistent policy enforcement and unified accountability, unlike federated or hybrid models that distribute control across business units.

  • ✗

    Federated

    Why it's wrong here

    Federated governance distributes security responsibilities across business units or regions, each with its own team, coordinated through shared standards. A single centralised team defines the Centralised model instead. Federated is tempting where organisations span diverse regulatory jurisdictions, since local autonomy aids compliance, but it contradicts the single-team requirement.

  • ✗

    Decentralized

    Why it's wrong here

    In decentralized model, security is embedded within business units, not centralized.

  • ✗

    Hybrid

    Why it's wrong here

    Hybrid governance blends centralised and decentralised elements, so some functions report centrally while others sit within business units. A single centralised team serving the whole organisation describes the Centralised model. Hybrid tempts large enterprises balancing global policy with local responsiveness, but its split structure fails the single-team criterion.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.