712-50 exam dumps

712-50 practice question 13 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 13

Single answerUnderstand standards, procedures, directives, policies, regulations, and legal issues that affect the information security program

A global manufacturing company headquartered in Germany acquires a smaller U.S.-based health technology firm. During post-acquisition integration, the CISO discovers that employee HR records for EU staff, protected health information collected by the U.S. subsidiary, and security logs from both companies are being centralized into a single cloud platform. Business leaders want one unified information security policy issued immediately across all entities. The CISO is concerned that simply publishing a single policy without reconciling legal, regulatory, and internal governance requirements could expose the organization to compliance failures and weak accountability. Which action should the CISO take FIRST to build a defensible information security program?

  1. A

    Perform a legal and regulatory obligation mapping exercise to identify applicable laws, contractual requirements, and internal policy conflicts, then use the results to define policy exceptions, standards, and procedures for each business context

  2. B

    Adopt the stricter requirement from each jurisdiction and apply all of them universally in a single global procedure, because the highest standard automatically ensures compliance everywhere

  3. C

    Issue a corporate directive requiring all subsidiaries to follow headquarters' existing security policy immediately, and defer regional legal review until after technical controls are deployed

  4. D

    Focus first on harmonizing technical security baselines such as logging, encryption, and access control, because policy differences can be addressed later once operational integration is complete

Show answer and explanation

Correct answer: A

Explanation

In a CCISO context, this question tests the candidate's ability to distinguish among policies, standards, procedures, directives, regulations, and legal obligations, and to sequence governance decisions appropriately. A policy states management intent and direction; standards define mandatory control requirements; procedures describe how tasks are performed; directives are authoritative instructions; and all of these must align with binding legal and regulatory obligations. In mergers and acquisitions, the CISO should begin with an obligation mapping and gap analysis to determine which laws, regulations, contractual commitments, and internal governance documents apply to which data sets, business units, and geographies. This supports a risk-based, auditable control framework and avoids the common mistake of assuming that one corporate policy or the 'strictest rule wins' approach resolves all compliance issues. This approach is consistent with established governance and compliance practices reflected in frameworks such as ISO/IEC 27001 and 27002 for policy and control structure, NIST guidance on governance and risk management, and privacy compliance principles requiring organizations to understand applicable legal bases, data handling constraints, and accountability obligations before operationalizing controls.

  • A. Correct.

    Correct. The first step is to identify and map the organization's binding obligations and governance hierarchy: applicable laws and regulations (for example, GDPR for EU personal data and U.S. healthcare-related obligations where relevant), contractual commitments, records-retention requirements, cross-border transfer constraints, and existing corporate policies. A CISO should then translate those obligations into a coherent policy framework supported by standards, procedures, and documented exceptions. This approach establishes traceability from legal and regulatory requirements to control implementation and accountability, which is essential in a post-acquisition environment.

  • B. Incorrect.

    Incorrect. Applying the strictest rule everywhere may seem conservative, but it does not automatically ensure compliance. Legal obligations are often context-specific, jurisdiction-specific, and data-type-specific. Some requirements may conflict, impose different retention periods, or require specific governance mechanisms rather than simply stronger controls. Over-applying requirements can also create unnecessary operational burden or even create compliance problems if legal distinctions are ignored.

  • C. Incorrect.

    Incorrect. A top-down directive without prior legal and regulatory analysis is risky, especially in a multinational acquisition. Policies must be enforceable, aligned with applicable law, and supported by standards and procedures. Deferring regional legal review can result in noncompliant data handling, invalid cross-border processing assumptions, or inconsistent retention and monitoring practices. This option reflects a common governance mistake: assuming corporate authority overrides statutory obligations.

  • D. Incorrect.

    Incorrect. Technical baseline harmonization is important, but it should not precede understanding the obligations that determine what controls are required, where data may reside, how long records must be kept, who may access them, and what monitoring is permissible. Implementing controls before establishing the governing policy and legal requirements can lead to rework, poor audit defensibility, and noncompliant operations.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam