712-50 Question 116
Single answerManaging Laterally with CollaborationA newly appointed CISO is trying to improve cooperation between the information security team and peer business leaders. Several recent security initiatives have stalled because application owners, legal counsel, and operations managers felt security was imposing requirements without understanding business constraints. The CEO has asked the CISO to improve execution without reducing accountability for risk. Which action is the BEST first step for the CISO to take to manage laterally through collaboration?
- A
Establish a cross-functional governance forum with representatives from business, legal, IT operations, and application teams to jointly review priorities, risks, and decision criteria
- B
Require all business units to obtain security approval before starting any technology initiative so security can maintain control over risk decisions
- C
Escalate noncompliance directly to the CEO and board to demonstrate that security issues are enterprise risks rather than operational disagreements
- D
Move ownership of security-sensitive systems from business units to the security department so conflicting priorities are eliminated
Show answer and explanation
Correct answer: A
Explanation
In CCISO practice, managing laterally with collaboration requires the CISO to influence peers across business and support functions through governance, shared objectives, credibility, and communication rather than relying solely on hierarchy. The best first step in this scenario is to create a cross-functional forum or governance mechanism where stakeholders can jointly assess business priorities, legal obligations, operational constraints, and security risks. This aligns with widely accepted security leadership and governance practices reflected in frameworks such as ISO/IEC 27001 and ISO/IEC 27014, which emphasize leadership, stakeholder engagement, and governance structures, and with NIST guidance that promotes risk management as an enterprise activity involving business owners and supporting functions. The other options are plausible because CISOs do need authority, escalation paths, and clear accountability, but they are weaker here because they substitute control for collaboration and are more likely to create resistance than durable alignment.
- A. Correct.
Correct. Managing laterally means influencing peers and partner functions without relying primarily on direct authority. A cross-functional governance forum creates shared ownership, transparency, and a structured way to balance security, legal, operational, and business objectives. This approach improves alignment and execution while preserving accountability for risk treatment decisions. It is a strong first step because it addresses the root cause: lack of collaboration and shared decision-making.
- B. Incorrect.
Incorrect. This approach increases central control, but it does not improve lateral collaboration. It is likely to reinforce the perception that security is a gatekeeper and may slow delivery, create workarounds, and weaken relationships with peer leaders. While security review may be appropriate within governance processes, making security a unilateral approval authority is generally not the best first step in this scenario.
- C. Incorrect.
Incorrect. Executive escalation can be necessary for unresolved material risk, but using it as an initial operating model damages peer relationships and bypasses the collaborative mechanisms needed for sustainable execution. The scenario calls for improving cooperation, not immediately increasing top-down pressure. Frequent escalation is often a symptom of poor governance rather than a substitute for it.
- D. Incorrect.
Incorrect. Transferring system ownership to the security department is not practical in most enterprises and undermines the principle that business and operational leaders retain ownership of their processes and associated risks. Security should advise, govern, and enable, but not absorb ownership simply to remove disagreement. This choice reflects a misunderstanding of enterprise risk accountability and collaborative leadership.