712-50 Question 100
Single answerOrganizational Contextual Intelligence and AnalysisA newly appointed CISO joins a multinational manufacturing company that has grown through acquisitions. Each business unit has its own security controls, risk registers, and reporting practices. The board is preparing to approve a three-year digital transformation program that will increase reliance on cloud services, third-party logistics providers, and connected factory systems. The CEO asks the CISO to recommend the MOST effective first step to ensure the security strategy is aligned with business objectives and organizational realities across the enterprise. What should the CISO do FIRST?
- A
Standardize all security controls immediately across every business unit using a single enterprise baseline
- B
Perform an organizational contextual analysis that maps business objectives, critical processes, regulatory obligations, risk appetite, and stakeholder dependencies before defining the target security strategy
- C
Acquire a new GRC platform so all business units can enter risks into a centralized system for executive reporting
- D
Benchmark the current security program against peer manufacturers and adopt the industry-average control set as the target model
Show answer and explanation
Correct answer: B
Explanation
In CCISO practice, organizational contextual intelligence and analysis require the CISO to begin with the business context, not with controls or tools. The most effective first action is to understand the enterprise's mission, strategic initiatives, operating model, stakeholder expectations, compliance landscape, risk appetite, and value chain dependencies. This aligns with widely accepted security leadership practices reflected in frameworks such as NIST CSF 2.0 Govern (understanding organizational context, requirements, and risk management strategy), ISO/IEC 27001 and 27005 principles for aligning information security and risk treatment with organizational context, and governance concepts from COBIT emphasizing enterprise goals alignment. In this scenario, acquisitions, cloud transformation, third-party logistics, and connected factory systems make context especially important because risks differ across IT, OT, supply chain, and regional regulatory environments. A mature CISO should first develop a clear view of that context, then define target-state governance, risk prioritization, and control harmonization accordingly.
- A. Incorrect.
This is incorrect because immediately enforcing a uniform control baseline assumes the acquired business units have the same business model, threat exposure, legal obligations, operational constraints, and risk tolerance. In a complex enterprise, standardization may eventually be appropriate in some areas, but doing it first ignores organizational context. A CCISO is expected to understand business drivers before prescribing controls, especially when digital transformation, OT environments, and third-party dependencies create materially different risk conditions across units.
- B. Correct.
This is correct because organizational contextual intelligence starts with understanding how the enterprise creates value, what its critical processes are, which stakeholders influence priorities, what regulatory and contractual obligations apply, and how leadership defines risk appetite and strategic direction. By mapping these factors first, the CISO can build a security strategy that supports business outcomes, prioritizes the most important risks, and accounts for differences among acquired entities, cloud adoption plans, supply chain exposures, and connected factory environments. This is the strongest first step before selecting controls, tools, or governance workflows.
- C. Incorrect.
This is incorrect because a GRC platform can improve consistency and reporting, but technology should not precede understanding. If the organization has not yet harmonized risk criteria, business priorities, ownership models, or reporting expectations, centralizing inputs into a tool may simply scale inconsistency. This is a common mistake: treating governance tooling as a substitute for contextual analysis and strategy development.
- D. Incorrect.
This is incorrect because industry benchmarking can provide useful external perspective, but adopting an industry-average control set does not ensure alignment with this specific organization's strategy, acquisitions, operational technology footprint, third-party ecosystem, or board-level risk appetite. Benchmarking is a supporting input, not the primary first step. The misconception is that peer comparison alone is sufficient to define what the organization needs.