712-50 Question 104
Single answerCommunicating ChangeA newly appointed CISO is rolling out a change to the organization’s remote access policy after several audit findings showed inconsistent use of multifactor authentication (MFA) and unmanaged personal devices. The change will require all remote users to enroll in MFA and use company-managed endpoints within 90 days. Business unit leaders are concerned about productivity loss, while the CEO wants rapid adoption without damaging employee trust. Which action should the CISO take FIRST to communicate this change effectively and improve the likelihood of successful adoption?
- A
Issue a company-wide email immediately announcing mandatory enforcement dates and penalties for noncompliance
- B
Work with executive sponsors and business leaders to tailor the message by stakeholder group, explaining the business rationale, impact, timeline, and support model
- C
Delay broad communication until all technical controls are fully implemented to avoid confusion and questions
- D
Ask the IT help desk to communicate the change informally during support calls so employees hear about it only when relevant
Show answer and explanation
Correct answer: B
Explanation
The best answer is to establish a structured, stakeholder-specific communication approach backed by leadership before broad rollout. In CCISO practice, communicating change is not just about announcing a new control; it is about aligning the change to business objectives, risk posture, compliance needs, and user impact. Good practice includes identifying stakeholders, securing executive sponsorship, tailoring messages, setting realistic timelines, defining support channels, and reinforcing communication throughout the transition. This aligns with broadly accepted change management principles found in frameworks and guidance such as Prosci change management practices, COBIT’s emphasis on stakeholder communication and governance alignment, and NIST guidance that highlights the importance of policy communication, role clarity, and user awareness in security program implementation. A CISO who communicates the rationale, impact, and support model effectively is more likely to achieve adoption while preserving trust and operational effectiveness.
- A. Incorrect.
This is incorrect because a one-way announcement focused on deadlines and penalties is typically insufficient for organizational change. While enforcement expectations must eventually be communicated, leading with punishment rather than context often increases resistance, reduces trust, and fails to address stakeholder-specific concerns. In change communication, especially for security-related initiatives that affect workflows, employees and managers need to understand why the change is necessary, what is changing, when it will happen, and how they will be supported.
- B. Correct.
This is correct because effective change communication starts with stakeholder-aware messaging supported by leadership alignment. By engaging executive sponsors and business leaders, the CISO can frame the change in terms of risk reduction, audit remediation, business continuity, and user impact. Tailoring communication by audience helps address different concerns: executives need business risk and compliance context, managers need operational implications, and end users need clear instructions, timelines, and support channels. This approach improves credibility, reduces resistance, and supports adoption through coordinated messaging rather than a purely technical announcement.
- C. Incorrect.
This is incorrect because delaying communication until implementation is complete is a common change management mistake. For a significant policy and process change, stakeholders need advance notice to prepare, budget time, manage staffing impacts, and raise legitimate concerns. Waiting too long can create surprise, rumors, and rushed adoption. Effective communication should begin early enough to set expectations and continue through implementation with updates and support information.
- D. Incorrect.
This is incorrect because relying on informal, reactive communication through the help desk is inconsistent and incomplete. The help desk is important for operational support, but it should reinforce a formal communication plan rather than replace it. Employees who only learn of a major policy change when they contact support may perceive the organization as disorganized, and many affected users may not receive the message in time to comply.