712-50 Question 145
Single answerManaging Difficult ConversationsA newly appointed CISO must address repeated delays by the Head of Product in remediating critical vulnerabilities before major releases. In the last steering committee meeting, the Product leader became defensive, argued that security is blocking revenue, and questioned the risk ratings in front of executives. A high-visibility launch is scheduled in two weeks, and the CEO has asked the CISO to resolve the conflict without damaging the cross-functional relationship. What is the BEST approach for the CISO to take next?
- A
Schedule a private meeting with the Head of Product, acknowledge the business pressure, present the specific risk in business terms, listen to the underlying constraints, and work toward a documented risk-based decision with clear owners and timelines.
- B
Send an email to the executive team restating the vulnerability severity scores, emphasizing that Product is accountable for any resulting breach, and request immediate remediation before release.
- C
Escalate directly to the CEO and recommend postponing the launch, since challenging security ratings publicly shows the Product leader is not taking cyber risk seriously.
- D
Reduce the severity ratings for the disputed vulnerabilities temporarily so the conversation can de-escalate and the release can proceed while the teams rebuild trust.
Show answer and explanation
Correct answer: A
Explanation
Managing difficult conversations at the executive level requires emotional intelligence, business alignment, and disciplined governance. The strongest response is to hold a private, constructive conversation that focuses on shared objectives, business impact, and decision rights rather than blame. This approach is consistent with established leadership and security governance practices: communicate cyber risk in business terms, understand stakeholder incentives and constraints, preserve relationships, and ensure decisions are documented through formal risk treatment or acceptance processes. In practice, this may include discussing remediation sequencing, compensating controls, phased releases, or acceptance within the organization's defined risk appetite. Broadly, this aligns with common guidance found in governance and risk frameworks such as ISO/IEC 27001 and ISO 31000, which emphasize risk-based decision-making, accountability, stakeholder communication, and formal treatment of residual risk. For a CCISO, the key is not just being technically correct, but resolving conflict in a way that supports the business while maintaining the integrity of the security program.
- A. Correct.
This is the best answer because it reflects effective executive leadership during a difficult conversation: move the conflict out of the public forum, address it directly and respectfully, translate technical risk into business impact, and seek to understand the Product leader's constraints before deciding on remediation, compensating controls, exception handling, or formal risk acceptance. It preserves the relationship while still protecting the organization. A documented risk-based decision with assigned owners and timelines aligns with governance expectations and ensures accountability.
- B. Incorrect.
This is incorrect because copying the executive team on a blame-oriented email is likely to harden positions, increase defensiveness, and damage trust. While written documentation is important, this approach turns a difficult conversation into a public confrontation and frames the issue as fault assignment rather than risk management. Executives typically expect the CISO to facilitate resolution, not intensify conflict through public shaming.
- C. Incorrect.
This is incorrect because immediate escalation to the CEO is premature unless the issue cannot be resolved through established governance channels or the risk is clearly outside delegated authority. Public disagreement does not by itself prove negligence. A CCISO-level leader should first attempt direct engagement, clarify facts, align on business impact, and use formal escalation only if risk tolerance is exceeded or impasse remains after reasonable effort.
- D. Incorrect.
This is incorrect because altering severity ratings to ease tension undermines the integrity of the risk management process and can expose the organization to unmanaged risk. It may temporarily reduce conflict, but it creates a governance and ethics problem and weakens trust in security assessments. A CISO should pursue calibration discussions if ratings are disputed, but not manipulate risk conclusions for political convenience.