712-50 exam dumps

712-50 practice question 131 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 131

Single answerSuccession Planning

A global manufacturing company is preparing for the planned retirement of its CISO in nine months. The board has expressed concern that several strategic security initiatives, including a zero-trust transformation and regulatory remediation program, depend heavily on the current CISO's personal relationships and undocumented decision-making processes. The CEO asks you, as deputy CISO, to recommend the MOST effective succession-planning action to reduce operational and governance risk before the transition. What should you do FIRST?

  1. A

    Identify a high-performing security manager and immediately announce that person as the next CISO to provide stability

  2. B

    Document the CISO's critical responsibilities, decision authorities, key stakeholder relationships, and required competencies, then assess internal candidates against those needs

  3. C

    Outsource strategic security leadership to a managed security service provider until the organization is ready to hire externally

  4. D

    Require each security team lead to submit a list of daily tasks so the replacement can maintain operational continuity

Show answer and explanation

Correct answer: B

Explanation

In CCISO practice, succession planning is a governance and resilience activity, not merely an HR replacement exercise. The first priority is to reduce key-person risk by formally defining the role's critical functions, authorities, business dependencies, and future-state competencies. For a CISO, this includes strategic program ownership, regulatory accountability support, incident decision authority, executive communications, board engagement, vendor and regulator relationships, and leadership capability. Once these elements are documented, the organization can perform a gap assessment of internal candidates, create development plans, establish transition timelines, and determine whether an external search is necessary. This aligns with common governance and business continuity best practices found in leadership succession frameworks, knowledge transfer planning, and enterprise risk management approaches. The key principle is that effective succession planning starts with role criticality and knowledge capture before naming or onboarding a successor.

  • A. Incorrect.

    This is not the best first step. Naming a successor before defining the role's critical accountabilities, leadership competencies, and business relationships can create avoidable risk. Succession planning should be role-based and aligned to enterprise strategy, not driven solely by current performance or speed of announcement. A strong manager may not have the executive, governance, regulatory, or board-facing capabilities required of a CISO.

  • B. Correct.

    This is correct because effective succession planning begins with identifying what must be preserved and transitioned: key responsibilities, delegated authorities, institutional knowledge, strategic initiatives, stakeholder relationships, and the competencies needed for future business objectives. Only after this analysis should the organization assess internal readiness, target development plans, or decide whether external recruitment is needed. This approach reduces key-person dependency and supports continuity in governance and execution.

  • C. Incorrect.

    This is not the most effective first action. An MSSP can provide operational services, but strategic leadership, risk ownership, business alignment, and executive accountability remain internal responsibilities. Using an external provider as a temporary replacement does not address the core succession issue of transferring leadership knowledge, authority, and governance responsibilities.

  • D. Incorrect.

    This is insufficient and too operationally narrow for CISO succession planning. Daily task lists may help with tactical continuity, but they do not capture the executive dimensions of the role, such as board reporting, enterprise risk decisions, regulatory commitments, budget prioritization, and cross-functional influence. Succession planning for a CISO must address strategic and governance responsibilities, not just routine tasks.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam