712-50 exam dumps

712-50 practice question 10 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 10

Single answerEstablish information security management structure

A newly appointed CISO at a global manufacturing company is redesigning the information security management structure after a major audit found inconsistent security practices across business units. Regional IT managers currently make most security decisions, the privacy office reports to legal, and operational technology (OT) security is handled separately by plant engineering. The CEO wants stronger accountability, while business unit leaders are concerned that a centralized model will slow operations. Which action should the CISO take FIRST to establish an effective information security management structure that aligns security governance with business needs?

  1. A

    Create an enterprise security governance model that defines decision rights, reporting lines, and accountability across corporate IT, privacy, and OT, supported by a cross-functional steering committee

  2. B

    Centralize all security decisions under the CISO immediately and require regional IT, privacy, and OT teams to obtain approval for any security-related activity

  3. C

    Leave the current federated structure in place and focus on issuing enterprise security policies so each business unit can interpret and implement them independently

  4. D

    Outsource governance design to an external consulting firm and postpone internal role definition until the target operating model is fully implemented

Show answer and explanation

Correct answer: A

Explanation

The best first step is to establish a governance model for information security management that clearly defines organizational structure, decision authority, accountability, and coordination mechanisms across related functions. In CCISO practice, establishing the management structure is fundamentally about aligning security leadership and oversight with business objectives, regulatory obligations, and operational realities. In a complex environment with decentralized IT, separate privacy reporting, and distinct OT ownership, the CISO should create a structure that clarifies enterprise versus local responsibilities and introduces formal governance forums such as a security steering committee. This reflects widely accepted practices in frameworks such as ISO/IEC 27001 and ISO/IEC 27014, which emphasize leadership, governance, assignment of responsibilities, and alignment of information security with organizational objectives. NIST guidance also supports clear roles, responsibilities, and risk governance across organizational levels. The key is not extreme centralization or policy issuance alone, but a structured operating model with defined decision rights and cross-functional accountability.

  • A. Correct.

    Correct. The first priority in establishing an information security management structure is to define governance: who makes which decisions, who is accountable, how reporting relationships work, and how key functions such as IT, privacy, and OT coordinate. A cross-functional steering committee helps balance centralized governance with business-unit input, which is especially important in complex organizations. This approach improves consistency without ignoring operational realities and supports executive oversight and risk-based decision-making.

  • B. Incorrect.

    Incorrect. Although stronger centralization can improve consistency, immediately forcing all security decisions through the CISO is typically impractical and can create bottlenecks, reduce business agility, and generate resistance. Effective governance is not just about central control; it is about clear accountability, escalation paths, and appropriate delegation. A mature structure usually distinguishes strategic oversight from operational execution.

  • C. Incorrect.

    Incorrect. Policies alone do not establish a management structure. If decision rights, reporting lines, and accountability remain unclear, business units will continue to interpret requirements differently, which was already identified by the audit as a problem. This option reflects the common misconception that policy publication by itself creates governance.

  • D. Incorrect.

    Incorrect. External advisors can help benchmark or facilitate design, but the CISO should not delay internal role clarity until a future-state model is completed. In practice, accountability and governance mechanisms should be established early, even if refinement continues later. Deferring role definition prolongs the existing inconsistency and weakens executive control.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam