exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 583 discussion

Actual exam question from Isaca's CISM
Question #: 583
Topic #: 1
[All CISM Questions]

Which of the following is the GREATEST risk of centralized information security administration within a multinational organization?

  • A. Slower turnaround
  • B. Less uniformity
  • C. Less objectivity
  • D. Violation of local law
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
koala_lay
1 year, 3 months ago
Selected Answer: D
The greatest risk of centralized information security administration within a multinational organization is the violation of local law, option D. When a multinational organization centralizes its information security administration, it may face challenges in ensuring compliance with the diverse laws and regulations of different countries where they operate. Laws related to data privacy, data transfer, and cybersecurity can vary significantly between countries. Failing to comply with local laws can result in legal consequences, financial penalties, and damage to the organization's reputation. Therefore, it is crucial for multinational organizations to have a thorough understanding of local laws and establish appropriate measures to comply with them when centralizing their information security administration.
upvoted 3 times
...
oluchecpoint
1 year, 3 months ago
Selected Answer: D
D. Violation of local law The greatest risk of centralized information security administration within a multinational organization is the potential violation of local laws and regulations. When a multinational organization centralizes its information security administration, it may implement global security policies and practices that do not align with or comply with the specific legal requirements in each country or region where the organization operates. This can lead to legal issues, fines, and penalties, which can be much more significant and damaging than the other risks listed. While the other options (A. Slower turnaround, B. Less uniformity, C. Less objectivity) are also important considerations, they generally do not pose as significant a risk as violating local laws and regulations, which can have serious legal and financial consequences for the organization.
upvoted 1 times
...
richck102
1 year, 6 months ago
D. Violation of local law
upvoted 1 times
...
mad68
1 year, 7 months ago
Selected Answer: D
D. Violation of local law. Centralized information security administration involves consolidating the management and control of information security functions and activities into a centralized entity or team within the organization. While there are benefits to centralization, such as improved coordination, consistency, and efficiency, it also poses certain risks, particularly in a multinational context. One significant risk is the potential violation of local laws and regulations. Different countries have their own unique legal and regulatory requirements concerning data protection, privacy, and information security. These laws may vary in terms of data handling, storage, transfer, and access requirements
upvoted 2 times
...
Dravidian
1 year, 8 months ago
Selected Answer: C
I did go with D but I can see how C can be the answer here. With a centralized infosec administration your policies will have to be more subjective than objective since they cannot be applied in the same way across different regions since different factors like local laws and local cultures have to be considered.
upvoted 2 times
Salilgen
9 months, 4 weeks ago
Yes, but I think the GREATEST risk is violate local laws
upvoted 1 times
...
...
Souvik124
1 year, 10 months ago
D. Violation of local law is the greatest risk of centralized information security administration within a multinational organization.
upvoted 1 times
...
bambs
1 year, 10 months ago
Selected Answer: B
Centralized information security administration can create difficulties in balancing the need for consistency and standardization with the need for local customization and adaptation to meet the unique requirements of different countries and regions.
upvoted 1 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: D
D for sure
upvoted 2 times
...
aokisan
2 years ago
Selected Answer: D
centralized policy may violate local law.
upvoted 3 times
...
Ziggybooboo
2 years ago
Not sure why centralized would be less objective, D for me
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...