712-50 Question 112
Single answerManaging Up and Managing ExpectationsA newly appointed CISO has informed the board that the organization's ransomware risk will be "substantially reduced within six months" after implementing MFA, endpoint detection, and an offline backup program. Three months later, a business unit leader asks the CEO why phishing rates remain high and why recovery testing has not yet covered every critical application. The CEO tells the CISO that the board now believes the security program is behind schedule and may have been oversold. What should the CISO do FIRST to manage up effectively and reset expectations while maintaining credibility?
- A
Provide the CEO and board with a revised update that maps each initiative to measurable risk-reduction milestones, clarifies residual risk and dependencies, and distinguishes leading indicators from final outcomes
- B
Delay further communication until all recovery tests are completed so the next board update shows fully achieved results rather than partial progress
- C
Ask Internal Audit to present the status to the board instead, since an independent function will be viewed as more objective and reduce pressure on the CISO
- D
Escalate the business unit leader for creating confusion and recommend that all security questions be routed only through the CISO's office
- E
Issue a technical report showing detailed control deployment statistics to demonstrate that security engineering is progressing as planned
Show answer and explanation
Correct answer: A
Explanation
This scenario tests the CISO's ability to manage up after executive expectations were set too optimistically. In CCISO practice, managing expectations with senior leadership means communicating in terms of business risk, timelines, dependencies, residual risk, and measurable outcomes. A mature response is not defensive; it is to reset the narrative using clear milestones and transparent reporting. For example, MFA deployment may reduce account-compromise likelihood quickly, while backup maturity and recovery testing often require phased execution across application owners, infrastructure teams, and business continuity stakeholders. Likewise, phishing rates may remain high even while resilience improves if user reporting, email security tuning, and incident response workflows are still maturing.
Best practices reflected here align with widely accepted governance and security leadership principles found in frameworks such as NIST CSF 2.0 Govern and Measure functions, COBIT governance objectives around stakeholder communication and performance monitoring, and ISO/IEC 27014 governance concepts emphasizing informed decision-making, assurance, and alignment with organizational objectives. Boards generally should receive risk-based reporting with trends, assumptions, constraints, and residual exposure, not promises that imply elimination of risk. The strongest first action is therefore to provide a revised, business-focused update that converts broad claims into realistic milestones and explicitly explains what success looks like at each stage.
- A. Correct.
Correct. In a managing-up situation, the immediate priority is to reestablish a shared understanding with executive leadership by translating security activities into business-relevant milestones and outcomes. The CISO should clarify what has been delivered, what benefits should reasonably be visible now versus later, what dependencies exist across business units, and what residual risk remains even after the controls are implemented. This approach addresses the root problem: expectations were framed too broadly and progress was not tied to realistic, measurable outcomes. Boards typically need concise reporting on risk posture, assumptions, timelines, and decision points rather than generalized assurances.
- B. Incorrect.
Incorrect. Waiting for complete results worsens the expectation gap and can damage credibility further. Executive stakeholders need timely course correction, especially when prior statements may have implied faster or broader outcomes than the program can deliver. Effective managing up requires proactive communication of partial progress, constraints, and revised forecasts, not silence until all work is done.
- C. Incorrect.
Incorrect. Internal Audit can provide assurance, but it should not be used as a substitute for the CISO's responsibility to communicate program status and manage stakeholder expectations. Delegating the message at this point may appear evasive and does not resolve the underlying issue of aligning board expectations with realistic risk-reduction timelines.
- D. Incorrect.
Incorrect. While communication channels matter, treating the business unit leader as the problem is the wrong first move. The issue is not simply unauthorized questioning; it is that senior leadership interpreted the original message as a near-term promise of broad outcomes. A CISO must expect cross-functional questions and respond by improving transparency and stakeholder alignment, not by restricting inquiry.
- E. Incorrect.
Incorrect. Technical deployment metrics alone are usually insufficient for board-level expectation management. They may show activity but not whether the activity has changed business risk, where coverage gaps remain, or why some benefits take longer to materialize. Managing up requires contextualized, decision-oriented reporting rather than raw technical statistics.