CISM Certified Information Security Manager – Question0580

For an organization with operations in different parts of the world, the BEST approach for ensuring that security policies do not conflict with local laws and regulations is to:

A.
refer to an external global standard to avoid any regional conflict
B. make policies at a sufficiently high level, so they are globally applicable
C. adopt uniform policies
D. establish a hierarchy of global and local policies

Correct Answer: D