A CISO is developing a new information security program for a global organization with diverse business units and varying risk appetites. To ensure the program is both effective and accepted across the enterprise, which of the following approaches is MOST suitable for establishing security policies and standards?
- ADelaying policy development until all technical controls are fully implemented and operational.
- BImplementing a single, highly prescriptive set of global policies to ensure consistency and uniformity.
- COutsourcing policy development to a third-party consultant to ensure impartiality and expertise.
- DAdopting a federated approach, allowing business units to tailor policies within an overarching framework.
Show answer & explanationAnswer & explanation
Correct answer: D. Adopting a federated approach, allowing business units to tailor policies within an overarching framework.
A federated approach allows for a balance between centralized governance and local autonomy. It provides an overarching framework for consistency while enabling business units to adapt policies to their specific risks, regulatory requirements, and operational contexts, fostering greater acceptance and effectiveness in a diverse global organization.
Why the other options are wrong
- A. Policies and standards should guide control implementation; delaying them creates a program without clear direction and potentially misaligned technical efforts.
- B. A highly prescriptive, uniform approach often leads to resistance and non-compliance in diverse environments because it may not fit local needs.
- C. While consultants can assist, outsourcing the entire policy development risks disengagement from internal stakeholders and may not capture the organization's unique culture and risk appetite.
Federated Security Program
A security governance model where a central authority sets overarching policies and frameworks, while individual business units or regions have autonomy to implement and adapt specific controls and procedures.
- Balances centralization with decentralization.
- Promotes local ownership and relevance.
- Suitable for large, diverse, and global organizations.
Memory trick: For global security, 'Federate the Framework' for local fit.