Standardizing Security Programs During M&A
Two companies are in the process of merging. The companies need to decide how to standardize their information security programs. Which of the following would best align the security programs?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of governance frameworks in mergers; the trap is choosing technical baselines or isolated assessments over holistic structural alignment.
When merging companies, aligning their information security programs is best achieved by adopting a common cybersecurity framework. This page explains why shared frameworks provide the necessary structure for integration.
Candidates often choose CIS baselines because they are concrete, but these are too granular and lack the governance context needed for high-level program alignment.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Adopting a common Cybersecurity Framework (CSF), such as NIST CSF or ISO 27001, provides a standardized language and structure for risk management, governance, and control implementation. In a merger, this allows both entities to map their existing controls against a single taxonomy, identify gaps, and harmonize policies effectively.Why the Other Options Are Wrong
Shared deployment of CIS baselines (A) focuses on technical configuration standards rather than overall program governance. Joint best practices (B) are too vague and lack the mandatory structure of a formal framework. A vulnerability report (D) only identifies specific technical weaknesses and does not address the broader organizational or policy alignment required for merging security programs.Community Comment Notes
The community overwhelmingly selected Option C, noting that frameworks like NIST CSF provide a comprehensive approach to cybersecurity capabilities and risk management. As one commenter noted, "A cybersecurity framework... provides a structured and comprehensive approach," which is essential for integrating two distinct organizations.Official Reference
Exam Strategy
In GRC questions involving 'alignment,' 'standardization,' or 'mergers,' always look for the highest-level framework first. Technical controls are implementations; frameworks are the governing structures.
Frequently Asked Questions
Why isn't CIS Baselines the right choice for merging?
CIS Baselines are technical configuration guides. They do not provide the overarching governance, risk management, and policy structure needed to align two entire security programs.
What if the companies use different frameworks initially?
They should select one common framework (e.g., NIST CSF) and map both companies' existing controls to it to create a unified view and standard.