712-50 Question 15
Single answerUnderstand the enterprise information security compliance program and manage the compliance teamA newly appointed CISO is consolidating regional compliance activities after the company expanded through acquisition into three jurisdictions with different privacy and sector-specific regulatory requirements. Internal audit recently reported duplicated testing, inconsistent evidence collection, and missed remediation deadlines across the compliance team. The board has asked the CISO to improve regulatory readiness without significantly increasing headcount. Which action should the CISO take FIRST to establish a scalable enterprise information security compliance program and better manage the compliance team?
- A
Create a unified compliance governance model that maps regulatory obligations to common control requirements, assigns control owners, and defines centralized evidence and remediation tracking
- B
Increase the frequency of regional compliance assessments so each acquired business unit can independently demonstrate adherence to its local regulations
- C
Outsource all compliance monitoring activities to a specialized consulting firm to eliminate internal process inconsistencies
- D
Direct the compliance team to focus on the regulation with the largest potential fines first, delaying lower-risk obligations until the next audit cycle
Show answer and explanation
Correct answer: A
Explanation
An enterprise information security compliance program should be built on governance, control rationalization, accountability, and measurable oversight. In a multi-jurisdiction environment, the most effective first step is to map legal, regulatory, and contractual requirements to a common set of control objectives and then assign owners, evidence requirements, testing responsibilities, and remediation workflows. This reduces duplicated testing and supports consistent reporting to leadership and the board. The scenario specifically points to weak program structure rather than insufficient assessment volume. This approach aligns with widely accepted practices in governance and compliance management, including the use of common control frameworks, clear lines of responsibility, and centralized issue tracking reflected in sources such as ISO/IEC 27001 and 27002 control governance concepts, NIST's guidance on governance and risk management, and the general compliance oversight principles seen in the U.S. Sentencing Guidelines for effective compliance and ethics programs.
- A. Correct.
Correct. The first priority is to establish an enterprise compliance structure that normalizes obligations across jurisdictions into a common control framework, clarifies accountability, and standardizes evidence collection and remediation management. This addresses the root causes described in the scenario: duplication, inconsistency, and missed deadlines. A unified governance model enables the compliance team to scale by testing shared controls once where appropriate, maintaining traceability from regulation to control, and managing remediation through defined ownership and reporting.
- B. Incorrect.
Incorrect. Increasing assessment frequency may create more work and further duplicate effort without addressing the underlying management problem. If evidence collection, control ownership, and remediation tracking are inconsistent, additional assessments will likely amplify inefficiency rather than improve compliance readiness. This option reflects the common misconception that more auditing automatically improves compliance maturity.
- C. Incorrect.
Incorrect. Outsourcing can provide expertise or temporary capacity, but it does not eliminate the CISO's responsibility to establish governance, accountability, and oversight of the compliance program. Without an internal control framework and clear ownership model, an external provider may simply operate within the same fragmented environment. This option is plausible because organizations often use third parties for compliance support, but it is not the best first action.
- D. Incorrect.
Incorrect. Prioritizing by financial penalty alone is too narrow for enterprise compliance management. Effective compliance programs use a risk-based approach that considers legal obligations, business impact, customer commitments, operational dependencies, and shared control coverage. Delaying other obligations without a formal integrated program can increase exposure and worsen coordination problems across the team.