nerdexam
Isaca

CISM · Question #372

A global organization is planning to expand its operations into a new country with stricter data protection regulations than those in the headquarters' home country. Which of the following is the BEST

The correct answer is C. Work with legal to interpret the local regulatory requirements and implement applicable controls.. The best approach is to work with legal experts to interpret the local regulatory requirements and implement applicable controls. This ensures that the organization complies with the stricter data protection laws of the new country while maintaining alignment with business object

Submitted by renata2k· Apr 18, 2026Information Security Governance

Question

A global organization is planning to expand its operations into a new country with stricter data protection regulations than those in the headquarters’ home country. Which of the following is the BEST approach for adopting these new requirements?

Options

  • AProcure cybersecurity insurance that covers potential breaches and incidents in the new country.
  • BEnsure local operations comply with geographical data protection laws of the headquarters.
  • CWork with legal to interpret the local regulatory requirements and implement applicable controls.
  • DAdjust organization-wide security polices to align with regulations of the new country.

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    13% (6)
  • C
    59% (27)
  • D
    22% (10)

Explanation

The best approach is to work with legal experts to interpret the local regulatory requirements and implement applicable controls. This ensures that the organization complies with the stricter data protection laws of the new country while maintaining alignment with business objectives and mitigating potential legal and regulatory risks.

Topics

#Regulatory Compliance#Data Protection Laws#Legal Interpretation#Global Expansion

Community Discussion

No community discussion yet for this question.

Full CISM Practice