712-50 Question 152
Single answerRole Modeling Ethical LeadershipA newly appointed CISO joins a global company shortly after a significant insider misuse incident. During the first executive meeting, the CEO says, "We need to restore confidence quickly, so let's keep this issue within a very small circle and avoid discussing it with business unit leaders until we have perfect evidence." At the same time, the CISO learns that one of the highest-performing security managers bypassed the formal exception process months earlier to accelerate a deployment, and several team members now view policy compliance as optional for senior staff. To most effectively demonstrate ethical leadership and reset the security culture, what should the CISO do FIRST?
- A
Privately document the concerns, immediately launch disciplinary action against the security manager, and delay broader communication until legal counsel completes its review
- B
Model transparency and accountability by recommending a need-to-know but timely escalation to relevant business leaders, disclose that policy exceptions must follow governance regardless of rank, and require the manager's case to be handled through the same fair process used for others
- C
Focus on reassuring the board that the incident is contained, because visible executive confidence is more important than discussing internal ethical inconsistencies at this stage
- D
Issue a strongly worded reminder that all violations will result in termination, but avoid revisiting the prior manager's conduct to prevent harming morale
- E
Delegate the matter to HR and internal audit, because ethical leadership is best preserved when the CISO avoids direct involvement in personnel-related issues
Show answer and explanation
Correct answer: B
Explanation
The scenario tests whether the candidate understands that role modeling ethical leadership is demonstrated through actions, not slogans. In CCISO practice, ethical leadership includes setting the tone at the top, promoting transparency appropriate to stakeholder need, enforcing policies consistently, and ensuring accountability applies equally to high performers and senior personnel. The best response is to communicate in a timely, risk-informed manner to those who have governance or operational responsibility, while also using established exception, investigation, and disciplinary processes rather than ad hoc action.
This aligns with broadly accepted governance and ethics principles found in frameworks and guidance such as ISACA COBIT governance concepts, the NIST Cybersecurity Framework's emphasis on governance and organizational roles, and common corporate ethics and compliance practices. These sources consistently support clear accountability, documented decision-making, stakeholder communication, and consistent enforcement of policy. A chief security leader who visibly follows these principles helps restore trust, strengthens culture, and reduces the perception that policy is optional for influential individuals.
- A. Incorrect.
This is not the best first action. Documenting concerns is appropriate, and legal review may be necessary, but immediately moving to disciplinary action before established fact-finding and due process can undermine fairness. Delaying communication too long also conflicts with ethical leadership because it may prioritize image management over responsible transparency and risk ownership. A CCISO should reinforce governance and integrity, not appear reactive or selective.
- B. Correct.
This is the best answer. Ethical leadership at the executive level requires tone from the top, consistency, fairness, and transparent governance. The CISO should recommend timely communication to stakeholders with a legitimate need to know, rather than waiting for 'perfect' evidence if risk management decisions are needed now. Just as importantly, the CISO must demonstrate that policy exceptions are governed consistently regardless of performance or seniority. Handling the manager through the same established process shows accountability without favoritism and helps rebuild trust in the control environment.
- C. Incorrect.
This is incorrect because it elevates optics over ethics. Reassuring the board may be necessary, but ethical leadership is not primarily about projecting confidence; it is about honest communication, accountability, and consistent standards. Ignoring internal inconsistency sends a message that outcomes matter more than conduct, which weakens culture and can increase future misconduct risk.
- D. Incorrect.
This is incorrect because it relies on fear-based messaging without addressing leadership hypocrisy or procedural fairness. A blanket threat may appear decisive, but if prior misconduct by a high performer is ignored, employees will see enforcement as inconsistent. Ethical role modeling requires leaders to embody the standards they communicate and to apply them fairly, not simply issue punitive statements.
- E. Incorrect.
This is incorrect because the CISO cannot outsource ethical leadership. HR and internal audit have important roles in investigation, discipline support, and independent assurance, but the CISO remains responsible for setting security culture, reinforcing governance, and demonstrating principled leadership within the function and across the enterprise. Avoiding involvement would weaken the leadership signal.