712-50 exam dumps

712-50 practice question 138 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 138

Single answerTeam Building, Consensus Building, and Building Commitment

A newly appointed CISO is leading a cross-functional initiative to implement enterprise-wide data classification and handling standards. The security team supports the effort, but business unit leaders argue the program will slow operations and create extra work. Previous security initiatives failed because leaders felt policies were imposed without understanding operational realities. The CEO has asked the CISO to gain lasting commitment across the organization, not just issue a policy. Which action should the CISO take FIRST to build consensus and commitment while preserving momentum?

  1. A

    Publish the standard immediately with executive sponsorship from the CEO, then require each business unit to comply within 30 days

  2. B

    Form a cross-functional working group with representatives from key business units, legal, compliance, and operations to identify concerns, define shared objectives, and co-develop an implementation roadmap

  3. C

    Delegate ownership of the initiative entirely to the compliance department since regulatory drivers will create the strongest incentive for adoption

  4. D

    Begin technical enforcement through data loss prevention and access controls before consulting stakeholders, so resistance does not delay progress

Show answer and explanation

Correct answer: B

Explanation

The strongest first step is to create a cross-functional structure that enables shared problem solving and ownership. In CCISO-level leadership, team building and consensus building are not about seeking unanimous agreement on every detail; they are about aligning stakeholders around common business and risk objectives, clarifying tradeoffs, and building enough commitment to execute sustainably. A cross-functional working group is a practical mechanism for this because it includes the people who will be affected by the change and who can identify process, legal, compliance, and operational implications early.

This approach reflects widely accepted security governance and change management practices. Frameworks such as NIST CSF 2.0 emphasize governance, stakeholder communication, and organizational context in cybersecurity decision-making. Similarly, ISO/IEC 27001 implementation guidance stresses leadership, roles, coordination, and integration of information security into organizational processes rather than treating security as a standalone technical function. Change management best practices also support early stakeholder engagement to reduce resistance and increase adoption.

The key leadership principle is that durable commitment comes from involvement, transparency, and shared accountability. Executive sponsorship remains important, and technical controls may eventually be necessary, but the first action in this scenario should be to engage stakeholders in designing a workable path forward.

  • A. Incorrect.

    This approach may create short-term compliance pressure, but it does not address the root cause of prior failure: lack of stakeholder involvement and operational buy-in. Executive sponsorship is important, but issuing a top-down mandate too early often produces passive resistance, minimal adoption, and workarounds. For team building and consensus building, leaders should first engage affected stakeholders and incorporate business realities into the program design.

  • B. Correct.

    This is the best answer because it directly addresses team building, consensus building, and commitment. A cross-functional working group creates shared ownership, surfaces operational constraints early, and allows stakeholders to help shape objectives, roles, timelines, and success measures. This increases trust and commitment because participants see their concerns reflected in the solution. It also preserves momentum by moving the initiative forward in a structured way rather than delaying indefinitely.

  • C. Incorrect.

    Compliance can be an important partner, but transferring full ownership to compliance is ineffective for an enterprise security initiative that changes business processes and culture. This option confuses regulatory pressure with organizational commitment. Lasting adoption requires business engagement, operational feasibility, and visible partnership between security and the business, not simply compliance-driven enforcement.

  • D. Incorrect.

    Technical controls can support policy implementation, but using enforcement before consultation is likely to deepen resistance and reinforce the perception that security is imposing change without understanding the business. In a cross-functional governance initiative such as data classification, premature enforcement can disrupt operations and damage trust. Effective CISOs sequence stakeholder alignment before broad enforcement unless there is an immediate, critical risk requiring urgent action.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam