712-50 exam dumps

712-50 practice question 120 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 120

Single answerIndustry Specific Challenges in Leading Organizations

A newly appointed CISO has been hired by a healthcare organization that recently acquired a fintech subsidiary and now offers patient financing through a mobile application. The board wants a single enterprise security strategy within 90 days. The healthcare business is primarily focused on protecting electronic protected health information (ePHI) and clinical system availability, while the fintech subsidiary is under pressure to meet payment security, anti-fraud, and consumer financial regulatory expectations. Which action should the CISO take FIRST to build an effective enterprise security strategy that addresses these industry-specific challenges?

  1. A

    Adopt the stricter of the two industries' control sets across the entire enterprise to create one uniform baseline as quickly as possible

  2. B

    Perform a business-driven risk and regulatory obligation mapping by data type, service, jurisdiction, and critical process before defining the target security operating model

  3. C

    Standardize all systems on the healthcare organization's existing HIPAA-oriented policies because patient trust is the organization's primary brand concern

  4. D

    Delay strategic integration until the fintech subsidiary completes its next external compliance assessment so the enterprise can rely on audited findings

Show answer and explanation

Correct answer: B

Explanation

The best first step for a CCISO leading across industries is to align security strategy to business services, regulatory obligations, and risk exposure rather than defaulting to the most familiar or most stringent framework. In this scenario, the organization operates in two sectors with materially different drivers: healthcare emphasizes confidentiality, integrity, and especially availability of clinical services and ePHI protections under the HIPAA Security Rule, while fintech may bring obligations related to payment data protection, fraud prevention, and financial consumer safeguards. A business-driven obligation mapping exercise helps the CISO define where controls can be standardized enterprise-wide and where industry-specific overlays are necessary. This is consistent with risk-based governance principles reflected in frameworks and guidance such as NIST Cybersecurity Framework 2.0, NIST SP 800-53 tailoring concepts, HIPAA Security Rule administrative/technical/physical safeguard expectations, and PCI DSS scoping principles. At the executive level, CCISO candidates are expected to avoid simplistic compliance-only thinking and instead build an operating model that reflects business criticality, data sensitivity, legal requirements, and board-level risk tolerance.

  • A. Incorrect.

    This is not the best first action. Using the stricter control set everywhere may sound conservative, but it can create unnecessary cost, operational friction, and misalignment with actual business processes and legal obligations. Healthcare and fintech face overlapping but different requirements, threat models, resilience expectations, and data handling patterns. A CCISO should first understand which regulations, obligations, and risks apply to which business services and data flows before prescribing a unified baseline.

  • B. Correct.

    This is correct. In a cross-industry environment, the CISO should begin by mapping obligations and risks to business processes, data types, jurisdictions, and critical services. That allows the enterprise to identify where healthcare requirements such as HIPAA Security Rule safeguards, availability of clinical systems, and privacy obligations intersect with fintech requirements such as PCI DSS scope, fraud management, consumer financial expectations, and potentially GLBA-related safeguards depending on the operating model. This approach supports a risk-based target operating model instead of a one-size-fits-all control decision.

  • C. Incorrect.

    This is incorrect because it prioritizes one business context based on brand perception rather than enterprise risk and regulatory reality. HIPAA-oriented policies are important for ePHI, but they do not fully address payment card security, fraud monitoring, financial data handling, or sector-specific oversight expectations in a fintech environment. A common executive mistake is assuming the legacy parent company's compliance framework is sufficient for the acquired business.

  • D. Incorrect.

    This is incorrect because strategic integration should not wait for a future external assessment. Audits and assessments are useful inputs, but they are point-in-time and often control-focused rather than business-model-focused. The CISO must establish a risk-informed strategy now, especially when the board has requested one within 90 days. Delaying action increases the likelihood of unmanaged regulatory gaps, duplicate controls, and unclear accountability.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam