712-50 Question 126
Single answerLeading People, Building Teams, and Mentoring Future Leaders (6 questions)A newly appointed CISO inherits a geographically dispersed security organization with high turnover among mid-level managers, inconsistent decision-making across regions, and no clear succession pipeline for critical leadership roles. The board has asked the CISO to reduce key-person risk and build long-term leadership resilience without significantly increasing headcount. Which action should the CISO take FIRST to create a sustainable leadership development approach?
- A
Identify high-potential staff, define leadership competencies tied to business and security objectives, and launch a structured mentoring and succession planning program for critical roles
- B
Replace underperforming managers quickly and centralize all leadership decisions with the CISO until consistency improves across regions
- C
Send all managers to the same external leadership training course and require completion within the next quarter
- D
Promote the strongest technical individual contributors into management roles to fill the leadership gap as soon as possible
Show answer and explanation
Correct answer: A
Explanation
In a CCISO context, leading people and building future leaders requires more than filling vacancies or offering generic training. The most effective first step is to create a leadership development framework grounded in business needs: identify critical roles, define the competencies required, assess current talent, and establish mentoring and succession plans. This reduces key-person risk and creates organizational resilience. Widely accepted leadership and governance practices support this approach, including succession planning, competency-based talent management, and mentoring as part of workforce development. This is also consistent with the spirit of control frameworks and guidance such as NIST SP 800-53 control families related to workforce management and role definition, as well as broader governance and human capital best practices used in enterprise security leadership. The other options are plausible because they may appear decisive, but they are either reactive, overly centralized, or based on the common misconception that technical expertise or one-time training alone produces effective leaders.
- A. Correct.
Correct. This is the best first action because it addresses the root problem systematically: leadership continuity, inconsistent management capability, and succession risk. A structured approach starts with identifying critical roles, defining the leadership competencies needed for those roles, assessing talent against those competencies, and then using mentoring and development plans to prepare future leaders. This aligns with executive-level people leadership practices and workforce planning principles. It is sustainable because it develops internal capability rather than relying only on replacement or ad hoc training.
- B. Incorrect.
Incorrect. Although poor performance may need to be addressed, immediately replacing managers and centralizing decisions with the CISO is not a sustainable leadership development strategy. It may temporarily improve consistency, but it increases dependency on the CISO, weakens local ownership, and does not build future leaders. It also risks damaging morale and retention if used as the first broad response.
- C. Incorrect.
Incorrect. External training can be useful, but sending all managers to the same course is a generic training response, not a targeted leadership development strategy. It does not start with role criticality, competency gaps, or succession needs. Training alone rarely builds a leadership pipeline unless reinforced through mentoring, coaching, stretch assignments, and performance management.
- D. Incorrect.
Incorrect. Strong technical performance does not automatically translate into effective people leadership. Promoting individual contributors too quickly is a common mistake that can create weak managers and increase turnover. Management roles require competencies such as coaching, delegation, conflict management, business communication, and strategic decision-making, which should be assessed and developed deliberately.