Certified Information Security Manager (CISM)Information Security ProgramHard

A global organization with diverse business units and varying risk appetites is consolidating its information security program. The CISO wants to ensure that the program effectively addresses the unique needs of each unit while maintaining overall organizational alignment. Which of the following governance models is MOST appropriate for this scenario?

  1. ADecentralized governance, allowing each business unit to develop its own security program.
  2. BFederated governance, combining centralized oversight with decentralized execution.
  3. CCentralized governance, with all security decisions made by the corporate CISO.
  4. DOutsourced governance, delegating all security decision-making to a third-party provider.
Show answer & explanation

Correct answer: B. Federated governance, combining centralized oversight with decentralized execution.

Federated governance (C) is ideal for large, diverse organizations. It provides the necessary balance by establishing global security policies and frameworks (centralized oversight) while allowing business units to tailor implementation and operational decisions to their specific risk profiles and needs (decentralized execution). This ensures consistency where needed and flexibility where appropriate.

Why the other options are wrong

  • A. Decentralized governance would lead to inconsistent security postures across the organization, making it difficult to achieve overall alignment and manage enterprise-wide risks effectively.
  • C. Centralized governance would struggle to adequately address the diverse needs and varying risk appetites of multiple business units, potentially leading to inefficiencies or unmet requirements.
  • D. Outsourced governance delegates decision-making, which might address resource constraints but would likely struggle to maintain the nuanced balance between diverse business unit needs and overall organizational alignment, and it removes internal control.

Federated Security Governance

A governance model that combines centralized strategic direction, policy setting, and oversight with decentralized operational execution and localized decision-making, balancing consistency with flexibility.

  • Suitable for large, diverse organizations.
  • Ensures enterprise-wide standards while allowing local adaptation.
  • Promotes shared responsibility and accountability.

Memory trick: Govern a big, diverse kingdom? Central rules for all, local lords for local problems.

More Information Security Program questions