If you thinking from device management perspective then its best to have prime infrastructure so that you can push one template(ex: ACL) to all WLCs in one shot.
or if you want to mitigates security risks by providing comprehensive visibility into who and what is connecting across the entire network infrastructure, and exceptional control over what and where they can go...then you must use trust-sec.
here is the guide:
http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_11_universal_wlc_config.pdf
Regards
Dont forget to rate helpful posts