712-50 Question 1
Single answerDomain 1: Governance, Risk, Compliance, and Audit Management (15%)A newly appointed CISO at a multinational healthcare company learns that different business units have been accepting cyber risks independently to avoid delays in digital transformation projects. During a board risk committee meeting, directors express concern that there is no consistent method for determining which risks can be accepted, mitigated, transferred, or escalated. The organization is also preparing for external audits related to healthcare privacy regulations and expects increased regulatory scrutiny after a recent industry breach. Which action should the CISO take FIRST to establish effective governance and improve defensibility during audits?
- A
Implement a centralized enterprise risk management framework with defined risk appetite, risk tolerance, ownership, and formal risk acceptance and escalation criteria approved by executive leadership
- B
Purchase additional cyber insurance so business units can transfer more risks while continuing to document exceptions locally
- C
Direct each business unit to maintain its own risk register and report only critical risks to the board on a quarterly basis
- D
Delay governance changes until the external audit is complete, then update policies based on any audit findings
Show answer and explanation
Correct answer: A
Explanation
This question tests the candidate's ability to prioritize governance actions in a real-world environment where risk decisions are fragmented across business units. In CCISO Domain 1, governance, risk, compliance, and audit management require the CISO to ensure that risk decisions are made within an enterprise-approved framework, with clear accountability and board visibility. The best first step is to create or formalize a centralized enterprise risk management structure for information security that defines risk appetite, risk tolerance, treatment options, ownership, and escalation thresholds.
This approach aligns with widely accepted practices from ISO 31000, which emphasizes integrated risk management and structured decision-making; ISO/IEC 27005, which provides guidance on information security risk management; and governance concepts in COBIT, which stress stakeholder-approved objectives, accountability, and oversight. It also supports the three lines model by clarifying management responsibility, oversight, and auditability. For regulated sectors such as healthcare, documented governance and risk acceptance processes are especially important because regulators and auditors often expect evidence that leadership has formally reviewed and approved material risks rather than allowing informal local exceptions.
The key principle is that risk acceptance must be governed at the appropriate authority level and tied to business objectives, not handled ad hoc by individual units. A defensible governance model improves consistency, supports compliance efforts, and gives the board meaningful insight into enterprise cyber risk.
- A. Correct.
Correct. The primary problem is inconsistent and decentralized risk decision-making without a governance structure. The CISO should first establish a centralized risk governance approach aligned to enterprise risk management principles. This includes defining risk appetite and tolerance, assigning risk ownership, standardizing assessment criteria, and creating formal processes for risk treatment, acceptance, and escalation. Executive approval is essential because risk acceptance is a business decision, not merely a technical one. This action also improves audit defensibility by demonstrating repeatable governance, documented accountability, and management oversight.
- B. Incorrect.
Incorrect. Cyber insurance can be part of a risk transfer strategy, but it does not solve the governance problem of inconsistent risk acceptance and poor oversight. Insurance also does not eliminate regulatory obligations or accountability for managing security and privacy risks. Choosing this first reflects the misconception that financial transfer can substitute for governance maturity.
- C. Incorrect.
Incorrect. Allowing each business unit to continue managing its own risk register independently perpetuates the inconsistency identified by the board. While local input is important, the CISO needs enterprise-wide standards, aggregation, and escalation criteria. Reporting only critical risks quarterly may also hide systemic issues and reduce timely executive visibility.
- D. Incorrect.
Incorrect. Waiting until after the audit is reactive and leaves the organization exposed in the meantime. External audits assess the effectiveness of current controls and governance, so postponing governance improvements weakens both operational risk management and audit readiness. This option reflects a common mistake of treating audit as the driver of governance rather than viewing governance as the foundation for compliance and audit success.