712-50 exam dumps

712-50 practice question 133 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 133

Single answerDelegation

A newly appointed CISO at a global manufacturing company has inherited an overextended security leadership team. Incident response decisions, third-party risk exceptions, awareness program approvals, and security architecture sign-off are all being routed to the CISO personally, causing delays in business projects and inconsistent follow-through. The board has asked the CISO to improve execution without weakening accountability. Which action is the MOST effective first step for the CISO to take when delegating these responsibilities?

  1. A

    Create a formal delegation model that assigns decision rights, authority limits, escalation thresholds, and reporting requirements to specific security leaders

  2. B

    Ask each security manager to take ownership of tasks they believe fit their role, while the CISO remains available for major issues

  3. C

    Delegate approval authority broadly to accelerate decisions, and review outcomes at the end of each quarter

  4. D

    Retain all exception approvals personally, but delegate operational activities such as documentation and meeting attendance

Show answer and explanation

Correct answer: A

Explanation

In senior security leadership, delegation is a governance activity, not merely a workload management tactic. The CISO remains accountable for outcomes, but execution improves when authority is distributed through a structured model with clear decision rights, limits, and escalation paths. This approach is consistent with widely accepted governance and control practices reflected in frameworks such as COBIT, which emphasizes defined roles and decision authority, and NIST guidance that supports documented roles, responsibilities, and oversight in security programs. In practice, a delegation model may use tools such as a RACI matrix, approval thresholds, exception criteria, and periodic reporting to ensure that delegated authority is exercised consistently and within risk appetite. The key principle is to delegate authority with controls, not just tasks without structure.

  • A. Correct.

    Correct. Effective executive delegation in a CISO context is not simply handing off work; it is transferring clearly defined authority within controlled boundaries while retaining accountability. A formal delegation model clarifies who can decide what, under which conditions, when escalation is required, and how oversight will occur. This reduces bottlenecks, improves consistency, and aligns with governance principles such as clear accountability, segregation of duties, and risk-based decision-making.

  • B. Incorrect.

    Incorrect. This is informal and role-ambiguous delegation, which often creates gaps, overlaps, and inconsistent risk treatment. Managers may interpret responsibilities differently, leading to uneven decisions and weak governance. A CISO should not rely on self-assignment of critical authority without defined boundaries and reporting expectations.

  • C. Incorrect.

    Incorrect. Broad delegation without authority limits or escalation criteria can create unmanaged risk, especially for areas like third-party exceptions or architecture approvals. Quarterly review is too infrequent for effective governance over high-impact security decisions. Delegation should increase speed, but not at the expense of control and accountability.

  • D. Incorrect.

    Incorrect. This preserves the original bottleneck by keeping key decision authority centralized with the CISO. Delegating only administrative or operational tasks may reduce minor workload, but it does not solve the strategic problem of delayed decisions and underdeveloped leadership capacity. Effective delegation should include appropriate decision-making authority, not just task execution.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam