CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium
A global manufacturing company is implementing a new enterprise resource planning (ERP) system that will store intellectual property, financial records, and employee data across its international subsidiaries. The CISO needs to ensure that data protection policies are consistent yet adaptable to local legal and cultural nuances. Which compliance strategy BEST addresses this requirement?
- ACentralized policy enforcement with no local variation.
- BGlobal Baseline with Local Override (GBwLO).
- CAdoption of the strictest regulation globally.
- DDelegated policy creation to each subsidiary.
Show answer & explanationAnswer & explanation
Correct answer: B. Global Baseline with Local Override (GBwLO).
Global Baseline with Local Override (GBwLO) is a compliance strategy that establishes a foundational set of security and data protection policies globally, while allowing for specific, documented deviations or enhancements at a local level to meet unique legal, regulatory, or cultural requirements. This balances consistency with adaptability.
Why the other options are wrong
- A. Centralized policy enforcement with no local variation fails to address local legal and cultural nuances.
- C. Adoption of the strictest regulation globally might be overly burdensome, costly, and still not address all specific local nuances.
- D. Delegated policy creation to each subsidiary would lead to inconsistency and potential compliance gaps across the organization.
Global Baseline with Local Override (GBwLO)
A compliance strategy that sets a global minimum standard for policies and controls, allowing for specific local adjustments.
- Ensures global consistency while accommodating local requirements.
- Prevents unnecessary over-compliance in some regions.
- Requires clear documentation and justification for local overrides.
Memory trick: Global Base, Local Grace.