712-50 Question 117
Single answerManaging Laterally with CollaborationA newly appointed CISO at a global manufacturing company is trying to improve collaboration with peer executives after several security initiatives were delayed by Operations, Legal, and Product teams. In the last quarter, the security team issued mandatory control requirements without involving affected departments early, which led to budget disputes, missed product release dates, and growing resistance to future security requests. The CEO has asked the CISO to improve cross-functional execution without weakening risk management. Which action should the CISO take FIRST to manage laterally and increase collaboration with peer leaders?
- A
Establish a cross-functional governance forum with Operations, Legal, Product, and Finance to jointly review business objectives, risk trade-offs, and implementation priorities for security initiatives
- B
Escalate all future disagreements to the CEO so business unit leaders understand that security decisions take precedence over operational concerns
- C
Require each department head to sign compliance attestations for security mandates before project funding is approved
- D
Delay security initiatives until the security team can independently produce a complete enterprise risk model with no input from peer departments
Show answer and explanation
Correct answer: A
Explanation
The best first action is to create a structured mechanism for peer collaboration and shared decision-making. In senior security leadership, managing laterally requires influence, negotiation, and alignment with business objectives rather than issuing one-way directives. A governance forum or steering committee with key peer leaders helps the CISO translate security requirements into business terms, identify dependencies, agree on acceptable risk trade-offs, and sequence initiatives realistically. This is consistent with widely accepted governance and leadership practices reflected in frameworks such as NIST CSF governance outcomes, ISO/IEC 27001 leadership and organizational context principles, and COBIT's emphasis on stakeholder alignment and governance structures. While escalation, attestations, and independent analysis each have a place, they are not the best first move when the core problem is poor collaboration across peer functions.
- A. Correct.
Correct. Managing laterally means influencing peers across the organization without relying primarily on command authority. A cross-functional governance forum creates shared ownership, surfaces business constraints early, and allows the CISO to align security priorities with operational, legal, product, and financial realities. This approach improves trust, reduces friction, and supports risk-informed decisions rather than unilateral mandates.
- B. Incorrect.
Incorrect. Escalation to the CEO may occasionally be necessary for unresolved material risk, but making it the default first step damages peer relationships and weakens lateral influence. It signals that the CISO is relying on hierarchy instead of collaboration and negotiation, which often increases resistance rather than improving execution.
- C. Incorrect.
Incorrect. Compliance attestations can support accountability, but using them as an initial mechanism to force agreement is transactional and punitive. It does not address the root cause in the scenario, which is lack of early engagement and shared prioritization. Departments may sign under pressure while remaining uncommitted, leading to poor implementation outcomes.
- D. Incorrect.
Incorrect. Building an enterprise risk model is useful, but excluding peer departments contradicts the goal of lateral collaboration. Risk decisions require business context from stakeholders who own processes, products, contracts, and budgets. Waiting for a fully independent model also delays action and reinforces the same siloed behavior that caused the problem.