SY0-701 Question 401
Single answer5.1 Summarize elements of effective security governance.A healthcare company recently expanded through acquisition and now has multiple business units handling patient data in different ways. During an internal review, leadership discovers that each unit created its own security rules, risk tolerance varies by department, and system owners are unclear about who is responsible for approving exceptions to security requirements. The CIO wants to establish a governance approach that aligns security decisions with business objectives, clarifies accountability, and ensures consistent oversight across the organization. Which action should the company take FIRST?
- A
Deploy a new SIEM platform to centralize logging from all business units
- B
Establish an enterprise security governance framework with defined policies, roles, responsibilities, and risk management authority
- C
Require all departments to perform quarterly vulnerability scans and submit results to IT operations
- D
Outsource exception approval to the managed security service provider handling incident response
Show answer and explanation
Correct answer: B
Explanation
The best answer is to establish an enterprise security governance framework with defined policies, roles, responsibilities, and risk management authority. Security governance is about directing and controlling security in a way that supports organizational objectives. In practice, this includes setting policy, assigning ownership, defining risk appetite/tolerance, establishing exception and approval processes, and ensuring oversight by leadership. Frameworks and best practices such as NIST Cybersecurity Framework governance outcomes, NIST SP 800-53 policy and governance-related controls, and ISO/IEC 27001 emphasize management direction, assigned responsibilities, and risk-based decision-making. In this scenario, the organization's main issue is not a lack of tools or isolated security tasks; it is the absence of a consistent governance structure. Once governance is established, the company can then standardize operational activities such as logging, scanning, exception handling, and reporting across business units.
- A. Incorrect.
This is incorrect because centralized logging can improve visibility and support monitoring, but it does not solve the core governance problem. The scenario highlights inconsistent policies, unclear accountability, and varying risk tolerance. A SIEM is a technical control, while governance starts with organizational direction, decision-making authority, and policy structure.
- B. Correct.
This is correct because effective security governance begins with establishing a formal framework that defines policies, standards, roles, responsibilities, and risk ownership. In this scenario, the organization needs consistent oversight, alignment with business objectives, and clear authority for approving exceptions. Governance provides the structure under which technical and operational controls are implemented.
- C. Incorrect.
This is incorrect because vulnerability scanning is a useful security activity, but it is not the first step when the underlying problem is inconsistent governance. Without defined policies, accountable owners, and enterprise risk direction, departments may scan inconsistently or interpret results differently. Operational tasks should follow a governance model, not replace it.
- D. Incorrect.
This is incorrect because exception approval is a risk acceptance decision that should remain with internal organizational leadership or designated risk owners, not be delegated to an external provider. A managed security service provider may advise on security operations, but governance accountability and risk authority stay with the organization.