712-50 Question 102
Single answerShifting from Analysis to Action for Organizational ChangeA newly appointed CISO has completed a 90-day assessment and identified major security gaps, including inconsistent access reviews, weak third-party oversight, and poor incident escalation. The board agrees with the findings but is frustrated that previous assessments also produced detailed reports with little measurable improvement. The CEO asks the CISO to present a plan that will convert analysis into visible organizational change within the next two quarters. Which action should the CISO take FIRST to maximize the likelihood of execution and sustained change?
- A
Launch all identified remediation projects at once to demonstrate urgency and show the board that security is acting decisively
- B
Translate the assessment results into a prioritized transformation roadmap with executive ownership, measurable milestones, resource requirements, and business-aligned success metrics
- C
Commission a deeper diagnostic review to validate the root causes before committing to any organizational changes
- D
Begin by updating all security policies and standards so the organization has a complete governance baseline before operational improvements start
Show answer and explanation
Correct answer: B
Explanation
The best first step is to turn assessment findings into a prioritized, accountable transformation roadmap. At the CCISO level, leadership is expected to bridge the gap between diagnosis and enterprise execution. That means defining risk-based priorities, assigning business and technical owners, securing resources, establishing milestones, and tracking outcomes through metrics meaningful to executives. This reflects common security leadership and governance best practices seen in frameworks such as NIST CSF, which emphasizes improvement planning and governance outcomes, and COBIT, which stresses aligning enterprise goals, ownership, and performance management. In practice, organizations fail not because they lack findings, but because they do not convert findings into a structured change program with accountability and measurable results. The correct answer demonstrates strategic execution, stakeholder alignment, and organizational change leadership rather than further analysis or administrative activity.
- A. Incorrect.
This is incorrect because starting all remediation efforts simultaneously usually overwhelms the organization, dilutes accountability, and creates change fatigue. In executive leadership, moving from analysis to action requires prioritization, sequencing, and assignment of ownership. While urgency matters, broad unfocused activity often produces little sustained improvement and makes it difficult to measure progress or manage dependencies.
- B. Correct.
This is correct because the key challenge is not discovering more issues, but operationalizing findings into an executable change program. A prioritized roadmap converts assessment output into action by identifying what must be done first, who owns each initiative, what resources are needed, how success will be measured, and how progress will be reported. This approach also aligns security change with enterprise objectives, which is critical for gaining lasting executive support and driving accountability across business functions.
- C. Incorrect.
This is incorrect because the scenario indicates the organization already has sufficient analysis and a pattern of inaction. Ordering another diagnostic review delays action and reinforces the failure mode the board is complaining about. Additional analysis may be appropriate later for specific workstreams, but it is not the best first step when leadership is demanding execution and visible progress.
- D. Incorrect.
This is incorrect because policy updates alone rarely create organizational change. Governance documents are important, but revising policies first without translating them into prioritized operational initiatives, ownership, and metrics often results in paper compliance rather than real risk reduction. A roadmap may include policy work, but policy revision should support execution rather than substitute for it.