CISM - Information Security Governance - Section 1.2

Identify legal, regulatory and contractual requirements that shape the information security governance framework.

Identify the legal obligations, regulatory requirements such as GDPR, and contractual requirements that directly influence the design of an information security governance framework. Distinguish which requirements impose mandatory controls and which permit the organisation to choose compliant implementation approaches.

Regulatory complianceLegal obligationsContractual requirementsGDPR

Practice question for this objective

Free sampleInformation Security Governancemedium

An organisation operates in a sector subject to several overlapping laws and regulations, and senior management is frustrated that compliance work is duplicated across departments. The information security manager has been asked to make legal and regulatory obligations a manageable input to the governance framework. What should the manager do first to achieve this?

  • AAdopt a single internationally recognised security framework and assume that certification against it will satisfy each applicable law and regulation.
  • BDevelop a consolidated register of applicable legal and regulatory obligations mapped to the controls that satisfy them. Correct
  • CAssign each department to track its own obligations independently so that the staff closest to each law retain ownership of it.
  • DSchedule an external audit of current compliance so an independent party can list the obligations the organisation is breaching.
Begin managing legal and regulatory requirements by building a consolidated obligations register mapped to the controls that satisfy them. Mapping applicable obligations to controls in a single register exposes overlaps so one control can evidence several requirements, which removes duplicated compliance effort and makes legal duties a governable input rather than scattered ad hoc work.

Why A is wrong: Certifying to one framework is appealing as a shortcut, but a framework does not automatically map to every jurisdiction-specific legal duty, so gaps and duplicated effort would persist undetected.

Why B is correct: A consolidated obligations register mapped to controls reveals where one control satisfies several requirements, removes duplicated effort, and turns scattered legal duties into a structured input the governance framework can manage.

Why C is wrong: Local ownership sounds responsive and is tempting, but leaving each department to track obligations independently is the very source of the duplication and inconsistency management already complained about.

Why D is wrong: An external audit can be valuable later, but commissioning one before the obligations are even catalogued is premature and costly, and it outsources understanding that the organisation needs to own internally.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Governance objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.