712-50 exam dumps

712-50 practice question 132 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 132

Single answerDelegation

A newly appointed CISO at a global manufacturing company is overwhelmed by daily requests for security exceptions, incident escalations, and audit follow-ups. The board has asked the CISO to spend more time on cyber risk strategy and regulatory engagement. The CISO plans to delegate more operational decision-making to direct reports, but is concerned about losing control and increasing risk. Which action is the BEST first step to delegate effectively while maintaining accountability?

  1. A

    Assign all recurring security decisions to the security operations manager and require weekly summary emails

  2. B

    Define decision rights, escalation thresholds, and reporting requirements for each delegated responsibility, then communicate them formally to stakeholders

  3. C

    Delegate only low-risk tasks and retain all decisions involving compliance, incidents, and third-party risk

  4. D

    Rotate delegation authority among senior team members each quarter so no single manager becomes a bottleneck

Show answer and explanation

Correct answer: B

Explanation

The best answer is to formally define decision rights, escalation thresholds, and reporting requirements before delegating. In executive security leadership, delegation must align with governance, risk tolerance, and accountability. A CISO can delegate authority for operational decisions, but accountability for the security program remains with the executive leader. Best practices from governance and control frameworks such as COBIT, NIST governance concepts, and common RACI-style accountability models support clarifying authority, accountability, and escalation paths before transferring decision-making. This approach enables the CISO to focus on strategic responsibilities while ensuring operational consistency, auditability, and risk-based oversight.

  • A. Incorrect.

    This is incorrect because simply assigning recurring decisions to one manager without clearly defining authority limits, escalation criteria, and accountability can create inconsistent decisions and governance gaps. Weekly summary emails provide visibility, but they do not establish a controlled delegation model. A common misconception is that reporting alone is enough to manage delegated authority; in practice, effective delegation requires explicit boundaries and decision rights.

  • B. Correct.

    This is correct because effective executive delegation begins with a clear governance structure: who can decide what, under which conditions, when to escalate, and how outcomes will be reported. This allows the CISO to shift operational workload while preserving accountability and oversight. In a CCISO context, delegation is not abdication; the CISO remains accountable for outcomes, so formalizing decision rights and escalation thresholds is the strongest first step.

  • C. Incorrect.

    This is incorrect because retaining all significant decisions defeats the purpose of delegation and keeps the CISO trapped in tactical work. While some highly sensitive matters may warrant executive involvement, a mature security organization delegates substantial authority through defined controls. This option reflects a common but ineffective approach where leaders delegate tasks but not decision-making authority.

  • D. Incorrect.

    This is incorrect because rotating authority may reduce dependency on one person, but it is not the best first step. Frequent changes in delegated authority can cause confusion, weaken accountability, and produce inconsistent risk decisions unless a governance framework already exists. Delegation should first be structured and documented before considering staffing or resiliency models.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam