Certified Information Security Manager (CISM)Information Security GovernanceMedium

A global organization is drafting its information security policy framework. Given its diverse operational footprint across multiple countries, which of the following is the MOST critical consideration for ensuring legal and regulatory compliance?

  1. APrioritizing compliance with industry-specific certifications like ISO 27001 over national laws.
  2. BImplementing a 'one-size-fits-all' policy to simplify management and reduce overhead.
  3. CAdopting the most stringent security standard from any operating country as the global baseline.
  4. DConducting a comprehensive jurisdictional legal and regulatory assessment for each operating region.
Show answer & explanation

Correct answer: D. Conducting a comprehensive jurisdictional legal and regulatory assessment for each operating region.

A comprehensive jurisdictional legal and regulatory assessment is essential to identify all applicable laws, regulations, and contractual obligations in each operating region. This allows for the development of a policy framework that is tailored and compliant across the diverse global footprint, avoiding penalties and legal issues.

Why the other options are wrong

  • A. Industry certifications are valuable but do not supersede mandatory national or regional laws and regulations.
  • B. A 'one-size-fits-all' approach is unlikely to meet diverse international legal and regulatory requirements.
  • C. While aiming high, this might lead to unnecessary burden or non-compliance in other areas due to conflicting requirements.

Jurisdictional Legal Assessment

The process of identifying and analyzing all applicable laws, regulations, and contractual obligations relevant to information security within each geographical region an organization operates.

  • Crucial for global organizations.
  • Ensures compliance with diverse legal landscapes.
  • Informs policy development and control implementation.

Memory trick: Know every law, in every land you play.

More Information Security Governance questions