712-50 exam dumps

712-50 practice question 103 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 103

Single answerShifting from Analysis to Action for Organizational Change

A newly appointed CISO has completed a 90-day assessment and identified several security weaknesses, including inconsistent access reviews, delayed patching in critical systems, and poor incident escalation between IT and business units. The executive committee agrees with the findings, but after three months little has changed because business leaders view the recommendations as "security work" rather than operational priorities. The CISO needs to shift from analysis to action and create measurable organizational change without losing executive support. What should the CISO do FIRST?

  1. A

    Launch all identified remediation projects immediately under the security department to demonstrate momentum and report weekly activity metrics to the executive committee

  2. B

    Translate the assessment results into a prioritized transformation roadmap with business-owned accountabilities, defined outcomes, timelines, and risk-based success measures approved by executive leadership

  3. C

    Commission a more detailed gap assessment to validate the original findings before assigning actions to business and IT leaders

  4. D

    Escalate the lack of progress to the board audit committee and request a formal directive requiring all business units to implement the security recommendations

Show answer and explanation

Correct answer: B

Explanation

A core leadership challenge for a CCISO is turning assessment results into enterprise action. In practice, security transformation succeeds when findings are reframed as business-risk reduction initiatives with named owners, deadlines, governance checkpoints, and measurable outcomes. This reflects established governance and risk management practices found in frameworks such as NIST Cybersecurity Framework 2.0 Govern function, ISO/IEC 27001 requirements for assigning responsibilities and treating risk, and general change management principles that emphasize sponsorship, accountability, and measurable objectives. The key issue in the scenario is not discovering more problems, but converting accepted findings into a prioritized roadmap embedded in business operations. That is why the CISO should first secure executive approval for a risk-based transformation plan with business-owned accountabilities.

  • A. Incorrect.

    This is not the best first step. While rapid action can create visible activity, having the security department run all remediation work reinforces the idea that security is solely a security-team responsibility. It also ignores the need for operational ownership by IT, HR, procurement, and business leaders. Weekly activity metrics may show motion, but they do not necessarily drive accountability for outcomes or sustainable change.

  • B. Correct.

    This is the best answer. To move from assessment to organizational change, the CISO should convert findings into an execution-oriented roadmap tied to business risk, assign clear ownership to the functions that must implement change, and define measurable outcomes such as patch cycle reduction, access review completion rates, and incident escalation SLAs. Executive approval is essential because it turns recommendations into enterprise priorities rather than advisory observations from the security team. This approach aligns with governance best practices, risk treatment planning, and change management principles.

  • C. Incorrect.

    This is a plausible but incorrect choice. Additional analysis is a common organizational reflex when there is resistance to acting on known issues. However, the scenario indicates that the executive committee already agrees with the findings. The primary problem is not lack of data, but lack of ownership and execution. Further assessment would likely delay remediation and contribute to analysis paralysis.

  • D. Incorrect.

    This is premature as a first action. Board escalation can be appropriate if management refuses to address material risk, but in this scenario executive support exists and the issue is failure to operationalize change. Going directly to the audit committee may weaken management relationships and signal that the CISO cannot drive execution through established governance channels. The better first step is to create an approved, accountable implementation plan.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam