Standardizing Security Programs During M&A

Answer Correct answer: C — Both companies following the same CSF provides the unified governance structure needed to standardize security programs during a merger.

Two companies are in the process of merging. The companies need to decide how to standardize their information security programs. Which of the following would best align the security programs?

  1. Shared deployment of CIS baselines
  2. Joint cybersecurity best practices
  3. Both companies following the same CSF Correct Answer
  4. Assessment of controls in a vulnerability report

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of governance frameworks in mergers; the trap is choosing technical baselines or isolated assessments over holistic structural alignment.

When merging companies, aligning their information security programs is best achieved by adopting a common cybersecurity framework. This page explains why shared frameworks provide the necessary structure for integration.

Candidates often choose CIS baselines because they are concrete, but these are too granular and lack the governance context needed for high-level program alignment.

Community Discussion (5 comments)

Hs1208 👍 6 Selected: C
Both companies following the same CSF (Option C): A cybersecurity framework, such as NIST Cybersecurity Framework (CSF), ISO 27001, or others, provides a structured and comprehensive approach to cybersecurity. Aligning both companies with the same framework allows for a common understanding and implementation of security controls, risk management, and overall security governance
shady23 👍 3 Selected: C
C. Both companies following the same CSF
7308365 👍 2
C: A cybersecurity framework(CSF) is a list of activities and objectives undertaken to mitigate risks. The use of a framework allows an organization to make an objective statement of its current cybersecurity capabilities, identify a target level of capability, and prioritize investments to achieve that target. This is valuable for giving a structure to internal risk management procedures and provides an externally verifiable statement of regulatory compliance. Frameworks are also important because they save an organization from building its security program in a vacuum, or from building the program on a foundation that fails to account for important security concepts. By having both companies follow the same CSF, they would be better able to align the security programs.
johnabayot 👍 1 Selected: C
correct answer!
LuckyAro 👍 4 Selected: C
Both companies following same CSF (Cyber Security Framework)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Adopting a common Cybersecurity Framework (CSF), such as NIST CSF or ISO 27001, provides a standardized language and structure for risk management, governance, and control implementation. In a merger, this allows both entities to map their existing controls against a single taxonomy, identify gaps, and harmonize policies effectively.

Why the Other Options Are Wrong

Shared deployment of CIS baselines (A) focuses on technical configuration standards rather than overall program governance. Joint best practices (B) are too vague and lack the mandatory structure of a formal framework. A vulnerability report (D) only identifies specific technical weaknesses and does not address the broader organizational or policy alignment required for merging security programs.

Community Comment Notes

The community overwhelmingly selected Option C, noting that frameworks like NIST CSF provide a comprehensive approach to cybersecurity capabilities and risk management. As one commenter noted, "A cybersecurity framework... provides a structured and comprehensive approach," which is essential for integrating two distinct organizations.

Official Reference

Exam Strategy

In GRC questions involving 'alignment,' 'standardization,' or 'mergers,' always look for the highest-level framework first. Technical controls are implementations; frameworks are the governing structures.

Frequently Asked Questions

Why isn't CIS Baselines the right choice for merging?

CIS Baselines are technical configuration guides. They do not provide the overarching governance, risk management, and policy structure needed to align two entire security programs.

What if the companies use different frameworks initially?

They should select one common framework (e.g., NIST CSF) and map both companies' existing controls to it to create a unified view and standard.

Related Analysis

← Back to SY0-601 Study Guide