Courseiva
hardMultiple SelectObjective-mapped

Challenges in Decentralized Information Security Governance

Which THREE of the following are challenges in implementing information security governance in a decentralized organization?

Quick Answer

The answer is inconsistent policy enforcement across business units, redundant security controls, and diverse regulatory compliance. These three challenges arise because decentralized organizations distribute authority to individual business units, which often develop their own security practices without a unifying framework, leading to gaps in policy adherence, duplicated or conflicting tools, and fragmented compliance with laws like GDPR or SOX. On the Certified Information Security Manager CISM exam, this question tests your understanding of governance structures and the pitfalls of autonomy without central oversight—a common trap is mistaking centralized incident response as a challenge when it is actually a missing solution, not a problem itself. Remember that decentralized governance struggles with consistency, efficiency, and regulatory alignment, while unified risk reporting remains an aspirational goal. A useful memory tip is to think of the three C’s: Consistency, Cost (redundancy), and Compliance—all of which suffer when security governance is spread too thin.

⚠ Common exam trap

Many exam-takers confuse the desired outcomes of governance (like unified reporting and centralized response) with the inherent challenges of a decentralized structure, leading them to select those as challenges rather than recognizing them as missing capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Redundant security controls and tools

In a decentralized organization, each business unit often selects its own security tools and controls, leading to redundant security controls and tools across the enterprise. This redundancy increases costs, creates management complexity, and can introduce gaps in coverage due to inconsistent integration. The lack of centralized oversight means that duplicate solutions for the same function (e.g., multiple endpoint protection platforms) are common, making unified monitoring and maintenance difficult.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Unified risk reporting

    Why it's wrong here

    Unified reporting is often a desired outcome, not an inherent challenge.

  • Redundant security controls and tools

    Why this is correct

    Each unit may purchase similar tools, increasing costs and complexity.

  • Centralized incident response

    Why it's wrong here

    Centralized response is typically lacking in decentralized orgs, causing challenges, but the phrasing here is 'centralized', which is not a challenge itself.

  • Diverse regulatory compliance requirements

    Why this is correct

    Different regions may have different laws, complicating governance.

  • Inconsistent policy enforcement across business units

    Why this is correct

    Different units may interpret or apply policies differently.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A hospital chain has separate security teams for each facility. There is no central coordination, leading to duplicate efforts and inconsistent patient data protection. The system's CISO wants to improve governance with minimal disruption. What should he do?

easy
  • A.Merge all teams into one central unit
  • B.Implement a top-down mandate for all policies
  • C.Create a governance committee with representatives from each facility
  • D.Outsource security to a third party

Why C: A governance committee with representatives from each facility establishes a federated governance model that aligns security practices across the hospital chain without restructuring teams. This approach enables consistent policy development, shared oversight, and coordination of patient data protection efforts while minimizing operational disruption, as each facility retains its existing team structure. It directly addresses the lack of central coordination and duplicate efforts by creating a collaborative decision-making body, which is a core principle of information security governance.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.