712-50 exam dumps

712-50 practice question 14 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 14

Single answerUnderstand standards, procedures, directives, policies, regulations, and legal issues that affect the information security program

A multinational company is integrating two recently acquired subsidiaries into a single enterprise information security program. One subsidiary operates in the EU and processes customer personal data, while the other supports U.S. healthcare clients and handles protected health information on behalf of those clients. The board has asked the CISO to quickly harmonize governance documents across the enterprise. The current draft proposes issuing one global security policy and then allowing business units to create their own procedures as needed. Before approving the draft, the CISO wants to ensure the program properly addresses legal and regulatory obligations while maintaining governance clarity. Which action should the CISO take FIRST?

  1. A

    Publish the global security policy immediately and defer legal and regulatory mapping until internal procedures are written by each business unit

  2. B

    Conduct a jurisdiction and regulatory obligation assessment, map requirements to enterprise policies and supporting standards, and define where localized directives or procedures are required

  3. C

    Adopt the strictest control requirement from any jurisdiction for all systems globally so separate legal review is no longer necessary

  4. D

    Delegate compliance ownership entirely to the legal department because regulatory interpretation should not be embedded in the information security program

Show answer and explanation

Correct answer: B

Explanation

The best first action is to perform a legal, regulatory, and jurisdictional requirements assessment and map those obligations into the governance hierarchy: policies at the enterprise level, standards that define mandatory control requirements, and procedures or directives that address local implementation needs. This reflects common security governance practice in frameworks such as ISO/IEC 27001 and ISO/IEC 27002, where organizations are expected to identify applicable legal, statutory, regulatory, and contractual requirements and incorporate them into the information security management system. It also aligns with governance principles found in COBIT, which emphasize translating external requirements into internal policies and controls. In this scenario, the EU subsidiary raises data protection issues such as GDPR-related obligations, while the U.S. healthcare-related business raises HIPAA-related considerations for safeguarding protected health information in applicable arrangements. A single global policy can be appropriate, but only if it is informed by a prior requirements analysis and supported by standards and localized procedures where needed. The key CCISO concept being tested is the executive responsibility to structure governance documents correctly and ensure legal and regulatory obligations are integrated into the security program rather than treated as an afterthought.

  • A. Incorrect.

    This is incorrect because it reverses the proper governance sequence. Enterprise policies should be informed by applicable legal, regulatory, and contractual obligations before publication. Deferring obligation mapping until after procedures are written creates a high risk of misalignment, duplicate effort, and noncompliance. In practice, business units may implement inconsistent procedures that fail to meet requirements such as GDPR obligations for personal data processing or HIPAA-related safeguards in healthcare contexts.

  • B. Correct.

    This is correct because the first step in harmonizing an enterprise security program across multiple jurisdictions is to identify and map applicable obligations, then translate them into policy, standards, and supporting procedures or directives. A CISO must distinguish between enterprise-level policy statements, mandatory standards, and localized implementation procedures. This approach supports defensible governance, demonstrates due diligence, and allows the organization to account for cross-border legal differences, sector-specific requirements, and contractual commitments without creating uncontrolled fragmentation.

  • C. Incorrect.

    This is incorrect because using the strictest requirement everywhere may seem conservative, but it is not a substitute for legal and regulatory analysis. Different laws impose different obligations, definitions, timelines, reporting duties, data subject rights, retention constraints, and processing conditions. Applying the strictest technical control universally may still fail to satisfy jurisdiction-specific legal requirements. It can also create unnecessary operational burden and conflict with business or legal requirements in some regions.

  • D. Incorrect.

    This is incorrect because compliance and legal interpretation are shared responsibilities. Legal counsel should advise on statutory and contractual interpretation, but the CISO remains accountable for embedding those requirements into the information security governance structure and control framework. Treating compliance as solely a legal function is a common governance mistake that leads to policies disconnected from operational security practices.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam