Certified Information Security Manager (CISM)Information Security GovernanceHard
A CISO is reviewing the enterprise's information security policy framework. The organization operates in multiple jurisdictions, each with distinct data residency and privacy regulations. To ensure the framework remains legally sound and consistently applied, which of the following is the MOST important characteristic for the overarching information security policy to possess?
- AIt must be highly detailed, providing explicit technical controls for all systems.
- BIt must be identical across all jurisdictions to ensure uniformity.
- CIt must be reviewed and approved annually by the legal department only.
- DIt must be flexible enough to accommodate local legal and regulatory requirements.
Show answer & explanationAnswer & explanation
Correct answer: D. It must be flexible enough to accommodate local legal and regulatory requirements.
Given multiple jurisdictions with distinct regulations, the overarching policy must be flexible enough to allow for necessary local adaptations while maintaining a consistent enterprise-wide standard where possible. Rigidity would lead to non-compliance in some regions or unnecessary overhead.
Why the other options are wrong
- A. Overly detailed technical controls in an overarching policy can make it difficult to adapt to diverse environments and change quickly. Technical details belong in standards and procedures.
- B. An identical policy across all jurisdictions is impractical and likely to lead to non-compliance if regulations differ significantly. Uniformity should be sought at a higher level, with flexibility for local mandates.
- C. While legal department approval is essential, annual review by legal *only* is insufficient. It requires broader stakeholder input (e.g., CISO, business units) and typically more frequent review for dynamic environments.
Policy Framework Flexibility
The ability of an information security policy framework to adapt and accommodate diverse operational contexts, technological changes, and specific legal/regulatory requirements across different jurisdictions while maintaining core security principles.
- Crucial for global organizations.
- Balances centralized governance with local compliance needs.
- Prevents unnecessary rigidity and promotes practical applicability.
Memory trick: For global security, be firm on core, but flexible on local law.