712-50 Question 115
Single answerManaging Down and SupportingA newly appointed CISO inherits a security organization with high analyst turnover, inconsistent incident handling, and repeated complaints from business unit leaders that the security team is "blocking work" without explaining risk. The CEO has asked the CISO to improve both team performance and business relationships within the next two quarters, without increasing headcount. Which action should the CISO take FIRST to best address managing down and supporting the team while aligning with executive expectations?
- A
Replace underperforming analysts immediately and require stricter escalation rules to enforce consistency
- B
Implement a formal operating model that clarifies roles, decision rights, service expectations, and coaching mechanisms, then use metrics and regular feedback to improve execution
- C
Centralize all security approvals with the CISO so business leaders receive consistent decisions from a single authority
- D
Acquire a new security orchestration platform to automate incident handling and reduce analyst workload
Show answer and explanation
Correct answer: B
Explanation
This question tests the CCISO's ability to apply leadership and organizational management principles to a real operational problem. In the domain of managing down and supporting, the CISO is expected to build clarity, accountability, and team effectiveness while maintaining alignment with business needs. The strongest first move is to establish an operating model: define roles and responsibilities, assign decision rights, document service expectations, create management routines such as one-on-ones and performance reviews, and measure outcomes. This addresses both internal dysfunction and external stakeholder frustration.
This approach is consistent with widely accepted security and governance practices. NIST Cybersecurity Framework emphasizes governance, roles, and continuous improvement. NIST SP 800-61 highlights the need for clearly defined incident response roles, communication paths, and process consistency. COBIT governance principles also support defining responsibilities, performance measures, and alignment between business objectives and IT/security services. From a leadership perspective, effective CISOs improve team capability through structure, coaching, and stakeholder engagement before resorting to major staffing changes or new technology purchases. In short, when the core issue is unclear management and inconsistent execution, the CISO should first fix the operating model and support mechanisms.
- A. Incorrect.
This is not the best first step. Although personnel changes may sometimes be necessary, immediately replacing staff does not address root causes such as unclear responsibilities, poor management cadence, weak coaching, and misaligned stakeholder expectations. Stricter escalation rules alone can increase frustration and bureaucracy if the underlying operating model is undefined. A CCISO should first stabilize structure, expectations, and management practices before making broad staffing changes.
- B. Correct.
This is the best answer. The scenario points to management and organizational issues: turnover, inconsistency, and poor business engagement. A formal operating model helps the CISO manage down by defining roles and accountability, and support the team through coaching, performance expectations, and feedback loops. Clarifying service expectations with the business also improves relationships and reduces the perception that security is arbitrarily blocking work. Using metrics such as incident handling quality, SLA adherence, rework rates, and stakeholder satisfaction supports continuous improvement without adding headcount.
- C. Incorrect.
This is a plausible but incorrect response. Centralizing approvals might create short-term consistency, but it weakens delegation, slows business operations, and creates a bottleneck around the CISO. It also does not develop the management capability of the team. In a mature security organization, the CISO should define decision rights and oversight, not become the operational approval point for all issues.
- D. Incorrect.
Automation can help, but this is not the best first action. Technology may reduce manual effort, yet the scenario primarily reflects leadership, process, and organizational support problems rather than a tooling gap. Automating a poorly defined process can institutionalize inconsistency. Best practice is to establish governance, workflows, and performance management first, then determine where tools can effectively support those processes.