nerdexam
Isaca

CISM · Question #36

A multinational organization is introducing a security governance framework. The information security manager's concern is that regional security practices differ. Which of the following should be…

The correct answer is D. Local regulatory requirements. When implementing a security governance framework in a multinational organization with differing regional practices, evaluating local regulatory requirements first is crucial due to their mandatory nature and potential impact on operations.

Submitted by stefanr· Apr 18, 2026Information Security Governance

Question

A multinational organization is introducing a security governance framework. The information security manager’s concern is that regional security practices differ. Which of the following should be evaluated FIRST?

Options

  • ATraining requirements of the framework
  • BGlobal framework standards
  • CCross-border data mobility
  • DLocal regulatory requirements

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    21% (6)
  • C
    4% (1)
  • D
    64% (18)

Why each option

When implementing a security governance framework in a multinational organization with differing regional practices, evaluating local regulatory requirements first is crucial due to their mandatory nature and potential impact on operations.

ATraining requirements of the framework

Training requirements are important but only after the core framework, which must account for legal obligations, is defined.

BGlobal framework standards

While global framework standards are the goal, they must be tailored and implemented in consideration of local legal realities.

CCross-border data mobility

Cross-border data mobility is a critical aspect, but its policies and controls are directly influenced by the underlying local regulatory requirements regarding data privacy and residency.

DLocal regulatory requirementsCorrect

Local regulatory requirements are legally binding and must be complied with; therefore, understanding these varied obligations across different regions is the foundational first step to ensure the security governance framework is compliant and effective globally. Non-compliance can lead to significant legal and financial penalties.

Concept tested: Security governance framework implementation

Source: https://nvlpubs.nist.gov/nistpubs/ir/2007/NIST.IR.7358.pdf

Topics

#Security Governance#Regulatory Compliance#Local Regulations#Multinational Context

Community Discussion

No community discussion yet for this question.

Full CISM Practice