CISM - Information Security Governance (17% of the exam) - Section 1.2

Identify legal, regulatory and contractual requirements that shape the information security governance framework.

Identify the legal obligations, regulatory requirements such as GDPR, and contractual requirements that directly influence the design of an information security governance framework. Distinguish which requirements impose mandatory controls and which permit the organisation to choose compliant implementation approaches.

Regulatory complianceLegal obligationsContractual requirementsGDPR

Practice question for this objective

Free sampleInformation Security Governancemedium

An organisation operates in a sector subject to several overlapping laws and regulations, and senior management is frustrated that compliance work is duplicated across departments. The information security manager has been asked to make legal and regulatory obligations a manageable input to the governance framework. What should the manager do first to achieve this?

  • AAdopt a single internationally recognised security framework and assume that certification against it will satisfy each applicable law and regulation.
  • BDevelop a consolidated register of applicable legal and regulatory obligations mapped to the controls that satisfy them. Correct
  • CAssign each department to track its own obligations independently so that the staff closest to each law retain ownership of it.
  • DSchedule an external audit of current compliance so an independent party can list the obligations the organisation is breaching.
Begin managing legal and regulatory requirements by building a consolidated obligations register mapped to the controls that satisfy them. Mapping applicable obligations to controls in a single register exposes overlaps so one control can evidence several requirements, which removes duplicated compliance effort and makes legal duties a governable input rather than scattered ad hoc work.

Why A is wrong: Certifying to one framework is appealing as a shortcut, but a framework does not automatically map to every jurisdiction-specific legal duty, so gaps and duplicated effort would persist undetected.

Why B is correct: A consolidated obligations register mapped to controls reveals where one control satisfies several requirements, removes duplicated effort, and turns scattered legal duties into a structured input the governance framework can manage.

Why C is wrong: Local ownership sounds responsive and is tempting, but leaving each department to track obligations independently is the very source of the duplication and inconsistency management already complained about.

Why D is wrong: An external audit can be valuable later, but commissioning one before the obligations are even catalogued is premature and costly, and it outsources understanding that the organisation needs to own internally.

See more CISM practice questions, answers explained.

Exam traps in Information Security Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The framework that the information security team has the most prior hands-on experience operating.

    Why it is wrong: Team familiarity lowers adoption effort and feels pragmatic, but selecting on internal comfort rather than fit can leave governance misaligned with business and regulatory expectations.

  • Retain every adopted control so the programme can claim the broadest possible coverage against the published framework during the next audit

    Why it is wrong: Tempting because broad coverage looks thorough, but keeping controls with no driver wastes resources and treats the framework as a checklist, not a governance tool.

  • Apply the single least restrictive requirement across all jurisdictions, because a uniform lenient baseline keeps compliance cost low while still meeting at least one applicable law everywhere.

    Why it is wrong: Tempting because uniformity is cheap and simple, but meeting only the most lenient rule leaves the firm in breach in every stricter jurisdiction that also applies to it.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.