712-50 Question 106
Single answerShaping Organization for Competitive AdvantageA global manufacturer is repositioning itself as a digital services company by launching connected products, predictive maintenance services, and a customer analytics platform. The CEO wants information security to help accelerate market entry and differentiate the company from slower competitors, while the CFO is concerned that security reviews are delaying product releases. As the CISO, which action would BEST shape the security organization to create competitive advantage while maintaining effective risk management?
- A
Centralize all security decisions under the CISO's office and require final approval for every product change before release.
- B
Embed security architects and risk advisors into product and business units, define risk appetite with executive leadership, and use standardized security-by-design patterns with measurable release metrics.
- C
Outsource most security governance activities to a managed security service provider so internal teams can focus solely on product delivery.
- D
Reduce formal security involvement in early design phases and rely on penetration testing immediately before launch to avoid slowing innovation.
Show answer and explanation
Correct answer: B
Explanation
The best answer is Option 2 because the question focuses on shaping the security organization to create competitive advantage, not merely enforcing compliance. At the CCISO level, this means designing an operating model that aligns security with strategic business goals, enables innovation, and manages risk through governance rather than through excessive control friction. Embedding security within product and business teams is consistent with modern operating models that emphasize business partnership, federated execution, and security-by-design. Establishing enterprise risk appetite with executive leadership is a core governance responsibility that ensures product decisions are made within agreed business tolerances. Standardized control patterns and measurable delivery metrics support both assurance and speed. This approach aligns with widely recognized practices from NIST's risk management guidance, secure-by-design principles, and governance concepts reflected in COBIT and ISO/IEC 27001, all of which emphasize aligning security with business objectives, integrating controls into processes, and using governance structures that support informed risk-based decisions.
- A. Incorrect.
This is incorrect because heavy centralization and mandatory CISO-level approvals for every change usually create bottlenecks, slow delivery, and position security as a gatekeeper rather than a business enabler. In a transformation toward digital products and services, the security organization should scale decision-making closer to the business through delegated authority, clear standards, and governance guardrails. A candidate might choose this option because centralized control can appear to improve consistency, but it typically undermines agility and does not support competitive advantage.
- B. Correct.
This is correct because it aligns the security operating model with business strategy. Embedding security architects and risk advisors into product and business units enables earlier risk identification, faster decision-making, and stronger partnership with revenue-generating teams. Defining risk appetite with executive leadership ensures that security decisions reflect enterprise priorities rather than isolated technical judgments. Standardized security-by-design patterns, reusable controls, and measurable release metrics help reduce friction, improve consistency, and demonstrate that security supports speed, trust, and market differentiation. This approach reflects mature governance and a business-aligned security function.
- C. Incorrect.
This is incorrect because outsourcing can supplement capabilities, but it does not replace the need for internal leadership over governance, business alignment, and strategic risk decisions. Managed providers may help with monitoring or operational tasks, but shaping the organization for competitive advantage requires security to be integrated with product strategy, innovation, and executive decision-making. Someone might select this option thinking outsourcing increases efficiency, but it weakens the strategic partnership needed for digital transformation.
- D. Incorrect.
This is incorrect because late-stage testing alone is a reactive model that usually finds issues after design choices are already embedded, making remediation slower and more expensive. It may create the illusion of speed up front, but it often increases downstream delays, rework, and business risk. Modern best practice is to shift security left through architecture input, threat modeling, secure development practices, and predefined control patterns rather than relying primarily on end-of-cycle testing.