A CISO is developing an information security program for a large, publicly traded company with a complex organizational structure and several distinct business units, each with its own P&L (profit and loss) responsibility. To ensure consistent security posture while respecting business unit autonomy, the CISO wants to implement a governance model that fosters shared responsibility. Which of the following models is MOST suitable for this scenario?
- AFederated security model with a central governing body and distributed security functions within business units.
- BCentralized security model with a single, authoritative security team.
- CDecentralized security model where each business unit manages its own security independently.
- DOutsourced security model where a third-party managed security service provider (MSSP) handles all security operations.
Show answer & explanationAnswer & explanation
Correct answer: A. Federated security model with a central governing body and distributed security functions within business units.
A federated security model is ideal for large, complex organizations with distinct business units and a need for both consistent security posture and business unit autonomy. It establishes central governance (policies, standards, oversight) while allowing business units to manage their day-to-day security operations, fostering shared responsibility.
Why the other options are wrong
- B. A centralized model would likely conflict with the business units' desire for autonomy and P&L responsibility.
- C. A decentralized model would lead to inconsistent security postures and potential gaps across the enterprise, failing to ensure consistent security.
- D. Outsourcing all security operations might address staffing issues but doesn't inherently provide the governance structure for shared responsibility or account for the distinct business unit P&L structures.
Federated Security Governance
A security governance model that combines centralized oversight and policy setting with decentralized execution and operational management, often used in large, complex organizations with autonomous business units.
- Balances consistency with autonomy.
- Central team sets strategy, policies, and standards.
- Business units implement and manage security locally.
- Fosters shared responsibility and accountability.
Memory trick: One Head, Many Hands, All Working Towards Security.