712-50 Question 113
Single answerManaging Up and Managing ExpectationsA newly appointed CISO is preparing for a quarterly board meeting after a recent phishing incident led to a limited payroll data exposure. The CEO is concerned the board may perceive the security program as ineffective and asks the CISO to present only technical remediation details to avoid 'unnecessary alarm.' At the same time, business unit leaders are frustrated by new email security controls because they believe the controls are slowing operations. Which action should the CISO take FIRST to manage up effectively while also setting realistic expectations across leadership?
- A
Reframe the board update around business impact, current risk posture, response actions, and a time-bound improvement roadmap, while aligning executives on what outcomes the new controls can and cannot deliver
- B
Accept the CEO's direction and focus the board presentation on malware indicators, email gateway tuning, and patch levels so the discussion stays technical and narrow
- C
Delay discussion with the board until the security team can demonstrate that phishing risk has been fully eliminated and user complaints have decreased
- D
Ask internal audit to present the incident instead, because an independent function will be perceived as more objective than the CISO
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because the core issue is not only incident reporting, but executive communication and expectation management. A CCISO is expected to manage up by giving the CEO and board a clear view of business risk, response effectiveness, and the tradeoffs associated with security controls. Board-level communication should be concise, risk-based, and tied to organizational objectives, rather than overly technical. At the same time, managing expectations across peer executives means explaining that security controls are designed to reduce likelihood and impact, not guarantee zero incidents, and that some usability or process cost may accompany stronger controls.
This aligns with widely accepted governance and security leadership practices. Board communication guidance from sources such as NIST Cybersecurity Framework governance-focused outcomes, NIST SP 800-61 for incident handling communication, and ISO/IEC 27014 on governance of information security all emphasize reporting that supports risk-informed decision-making. Similarly, effective security leadership practices stress transparency, accountability, and clear articulation of residual risk. In practical terms, the CISO should avoid both minimizing the event for political reasons and overwhelming leaders with technical details that do not support decisions. The most effective first step is to establish a business-oriented narrative, define realistic outcomes, and align stakeholders on both the value and limitations of the security program.
- A. Correct.
Correct. Managing up requires translating security issues into business-relevant terms for senior leadership and the board, not simply reporting technical details. In this scenario, the CISO should present the incident in terms of business impact, residual risk, legal or regulatory implications if applicable, response status, and measurable next steps. Just as importantly, the CISO should set expectations with executives and business leaders that email security controls reduce risk but do not eliminate it, and that some operational friction may be an intentional tradeoff. This approach demonstrates transparency, executive maturity, and alignment with governance responsibilities.
- B. Incorrect.
Incorrect. This is a common mistake when communicating upward. Board members and senior executives generally need decision-support information, not deep technical telemetry. Limiting the presentation to technical remediation also obscures the actual business significance of the incident and may undermine trust if leaders later feel material context was withheld. Technical appendices may be appropriate, but they should not be the main message.
- C. Incorrect.
Incorrect. Risk cannot be fully eliminated, especially for phishing and human-targeted attacks. Waiting to report until risk is 'fully eliminated' sets an unrealistic standard and delays governance oversight. Effective CISOs communicate early, accurately, and with appropriate context, including what has been done, what remains, and what level of residual risk is expected.
- D. Incorrect.
Incorrect. Internal audit has an important independent assurance role, but responsibility for communicating the security program's operational status and incident response posture typically remains with management, including the CISO. Delegating the discussion to audit to avoid discomfort is poor expectation management and can create confusion about accountability.