Certified Information Security Manager (CISM)Information Security ProgramHard

A CISO is developing an information security program for a large, publicly traded company with a complex organizational structure and several distinct business units, each with its own P&L (profit and loss) responsibility. To ensure consistent security posture while respecting business unit autonomy, the CISO wants to implement a governance model that fosters shared responsibility. Which of the following models is MOST suitable for this scenario?

  1. AFederated security model with a central governing body and distributed security functions within business units.
  2. BCentralized security model with a single, authoritative security team.
  3. CDecentralized security model where each business unit manages its own security independently.
  4. DOutsourced security model where a third-party managed security service provider (MSSP) handles all security operations.
Show answer & explanation

Correct answer: A. Federated security model with a central governing body and distributed security functions within business units.

A federated security model is ideal for large, complex organizations with distinct business units and a need for both consistent security posture and business unit autonomy. It establishes central governance (policies, standards, oversight) while allowing business units to manage their day-to-day security operations, fostering shared responsibility.

Why the other options are wrong

  • B. A centralized model would likely conflict with the business units' desire for autonomy and P&L responsibility.
  • C. A decentralized model would lead to inconsistent security postures and potential gaps across the enterprise, failing to ensure consistent security.
  • D. Outsourcing all security operations might address staffing issues but doesn't inherently provide the governance structure for shared responsibility or account for the distinct business unit P&L structures.

Federated Security Governance

A security governance model that combines centralized oversight and policy setting with decentralized execution and operational management, often used in large, complex organizations with autonomous business units.

  • Balances consistency with autonomy.
  • Central team sets strategy, policies, and standards.
  • Business units implement and manage security locally.
  • Fosters shared responsibility and accountability.

Memory trick: One Head, Many Hands, All Working Towards Security.

More Information Security Program questions