712-50 Question 11
Single answerEstablish a framework for information security governance monitoring (considering cost/benefits analyses of controls and ROI)A newly appointed CISO is building an information security governance monitoring framework for a global manufacturing company. The board has approved a limited security budget and wants quarterly reporting that shows whether major control investments are delivering business value. One proposed initiative is deploying privileged access management (PAM) across plants and corporate IT. The implementation cost is high, but internal audit has repeatedly cited excessive administrator privileges and weak oversight of third-party maintenance accounts. Which approach should the CISO use FIRST to ensure governance monitoring supports cost/benefit analysis and meaningful ROI reporting for this control initiative?
- A
Define governance metrics that map the PAM initiative to business risk reduction, expected control outcomes, implementation and operating costs, and post-deployment measures such as reduction in privileged account abuse incidents, audit findings, and effort spent on access reviews
- B
Deploy PAM immediately in the highest-risk plants and use the number of administrator accounts onboarded each quarter as the primary board-level metric because it is easy to measure and shows implementation progress
- C
Report the full PAM project cost to the board and explain that ROI is not applicable to security controls because their value is primarily compliance-driven and difficult to quantify
- D
Base ROI reporting on projected losses from a worst-case cyberattack scenario and consider the control justified if the estimated avoided loss exceeds the implementation cost
Show answer and explanation
Correct answer: A
Explanation
For CCISO-level governance monitoring, the key is to create a framework that allows leadership to determine whether a security control is both effective and worth the investment. That means defining, up front, how the control supports business objectives, what risk it is intended to reduce, what it will cost over its lifecycle, and what evidence will show success after deployment. In practice, this aligns with widely accepted governance and risk management principles found in frameworks such as COBIT, NIST Cybersecurity Framework, and ISO/IEC 27001/27004. These emphasize linking security activities to business objectives, measuring control effectiveness, and using meaningful metrics rather than relying only on technical implementation statistics. For cost/benefit and ROI considerations, security leaders often combine quantitative and qualitative measures, including reduction in audit findings, reduced likelihood or impact of incidents, operational efficiencies, and improved compliance posture. The best first step is therefore to define governance metrics and monitoring criteria that connect the PAM initiative to risk reduction, cost, and measurable outcomes, so the board can make informed decisions over time.
- A. Correct.
Correct. This is the strongest governance-first approach because it establishes a monitoring framework before or alongside implementation and links the control to business objectives, risk treatment, measurable outcomes, and total cost. For executive governance, metrics should go beyond activity counts to demonstrate whether the control reduces risk exposure and improves assurance outcomes. Including implementation and ongoing operating costs enables cost/benefit analysis, while measures such as reduced audit exceptions, fewer excessive privileges, improved timeliness of access recertification, and reduced privileged misuse incidents provide evidence of effectiveness and support ROI-style reporting.
- B. Incorrect.
Incorrect. This focuses on implementation activity rather than governance effectiveness. The number of accounts onboarded is a useful operational KPI, but by itself it does not show whether risk has been reduced, whether the control is cost-effective, or whether business value is being realized. Boards need outcome-oriented metrics tied to risk and assurance, not just deployment progress.
- C. Incorrect.
Incorrect. While security ROI can be difficult to measure precisely, dismissing ROI entirely is not appropriate for governance reporting at the executive level. Senior leadership should be able to evaluate whether a control investment is justified through a combination of risk reduction, avoided loss estimates, audit improvement, process efficiency gains, and strategic alignment. Treating security solely as a compliance expense is a common but incomplete view.
- D. Incorrect.
Incorrect. Worst-case scenario modeling can inform business cases, but using only a single extreme loss estimate is a weak basis for governance monitoring and ROI. It can overstate benefit, ignore likelihood, omit operational and recurring costs, and fail to provide measurable post-implementation indicators. A sound governance framework should use realistic risk scenarios, defined success criteria, and ongoing monitoring of actual control performance.