712-50 exam dumps

712-50 practice question 12 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 12

Single answerEstablish a framework for information security governance monitoring (considering cost/benefits analyses of controls and ROI)

A newly appointed CISO is building an information security governance monitoring framework for a global manufacturing company. The board has approved only limited funding for new controls and has asked for quarterly reporting that demonstrates whether security investments are reducing business risk. The company is considering two proposed controls: expanding endpoint detection across all plants and implementing a supplier risk monitoring platform. Historical incident data is incomplete, and business unit leaders disagree on how to measure value. Which approach should the CISO take FIRST to establish a governance monitoring framework that supports cost/benefit analysis and ROI-based decision making?

  1. A

    Create a governance scorecard that maps each proposed control to business objectives, risk scenarios, baseline metrics, target KPIs/KRIs, implementation and operating costs, and expected reduction in loss exposure

  2. B

    Deploy both controls immediately and use the number of security alerts generated in the first quarter as the primary basis for determining which investment delivered more value

  3. C

    Require each business unit leader to justify the controls independently, then prioritize the option supported by the largest business unit because it will produce the greatest enterprise ROI

  4. D

    Delay any governance monitoring until the organization has at least one full year of complete incident data, because ROI calculations are not meaningful without mature loss statistics

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because establishing a governance monitoring framework requires more than selecting controls; it requires a repeatable method for linking investments to business outcomes and risk reduction. In a CCISO context, the CISO should define governance measures that allow leadership to compare controls based on business alignment, total cost of ownership, implementation effort, and expected effect on enterprise risk. This often includes baseline measurements, target-state metrics, KRIs, KPIs, and assumptions used in cost/benefit analysis. Where direct loss data is limited, organizations commonly use risk scenarios, proxy indicators, maturity assessments, and trend analysis to support decisions.

This approach is consistent with recognized practices from COBIT, which emphasizes aligning governance objectives, performance management, and benefits realization, and from the NIST Cybersecurity Framework and NIST SP 800-55, which stress selecting meaningful measures tied to objectives and using them to monitor effectiveness. From an executive governance perspective, ROI should not be measured by technical outputs alone; it should be evaluated in terms of reduced exposure, improved resilience, compliance support, and business enablement relative to cost. The key leadership action is to build the measurement model first so that quarterly reporting to the board is credible, comparable, and decision-oriented.

  • A. Correct.

    Correct. This is the strongest first step because it establishes a governance monitoring framework tied to enterprise objectives and measurable outcomes, not just technical activity. A sound framework should define what business risk is being addressed, what baseline currently exists, what metrics will indicate success, what the full lifecycle cost of each control will be, and how the control is expected to reduce either likelihood, impact, or both. Even when historical incident data is incomplete, the CISO can use risk scenarios, assumptions, proxy measures, and trend-based metrics to support decision making. This aligns with governance practices in frameworks such as COBIT and NIST, which emphasize alignment to business objectives, defined performance measures, and ongoing monitoring.

  • B. Incorrect.

    Incorrect. Alert volume is not a reliable indicator of business value or ROI. More alerts may simply mean higher noise, better visibility, or poor tuning. Governance monitoring should focus on risk reduction, control effectiveness, business impact, and cost efficiency rather than raw operational output. This option reflects a common mistake of equating technical activity with business benefit.

  • C. Incorrect.

    Incorrect. Business input is important, but prioritizing based on the size or influence of a single business unit is not an enterprise governance approach. ROI and cost/benefit analysis should be based on enterprise risk, critical processes, exposure, and strategic objectives. This option represents a political rather than risk-based decision model, which weakens governance integrity.

  • D. Incorrect.

    Incorrect. Waiting for perfect data delays governance and investment decisions unnecessarily. Senior security leaders are expected to make informed decisions under uncertainty using available evidence, assumptions, and qualitative plus quantitative inputs. While better incident data improves analysis over time, a governance monitoring framework should begin with current data, documented assumptions, and iterative refinement.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam