712-50 Question 159
Single answerLeading Self (6 questions)A newly appointed CISO has inherited a security program that is technically competent but viewed by business leaders as difficult to work with. During her first 90 days, she notices that she reacts defensively in executive meetings when challenged about security spending, which reduces trust and limits collaboration. She wants to improve her own leadership effectiveness before launching a major transformation program. Which action is the BEST first step for the CISO to take under the CCISO domain of Leading Self?
- A
Conduct a structured self-assessment and gather candid 360-degree feedback from peers, direct reports, and business stakeholders to identify leadership blind spots and create a personal development plan
- B
Immediately reorganize the security leadership team so that more technically aligned managers attend executive meetings on her behalf
- C
Publish stricter security governance standards to demonstrate authority and reduce future executive challenges
- D
Delay engagement with executives until the transformation roadmap is complete and supported by detailed cost-benefit analysis
Show answer and explanation
Correct answer: A
Explanation
The best answer is to begin with self-awareness and feedback. In CCISO's Leading Self domain, senior security leaders are expected to demonstrate emotional intelligence, self-management, resilience, and a commitment to continuous improvement. When a CISO recognizes defensive behavior in high-stakes meetings, the most effective first step is to diagnose that behavior through structured reflection and stakeholder feedback rather than trying to compensate through organizational changes, stricter controls, or delay. This aligns with widely accepted executive leadership practices such as 360-degree feedback, development planning, and emotional intelligence-based leadership development. It also reflects broader governance and leadership guidance found in frameworks and bodies of knowledge such as ISACA's leadership-oriented governance principles, NIST's emphasis on risk communication and organizational roles, and common executive coaching practices for improving influence and trust. In short, before transforming the organization, the CISO should strengthen personal leadership capacity so that future security initiatives are more likely to gain executive support.
- A. Correct.
Correct. In the Leading Self domain, effective CISOs first build self-awareness, emotional intelligence, and executive presence. A structured self-assessment combined with 360-degree feedback helps identify behavioral triggers, communication gaps, and credibility issues that may be undermining influence. Creating a personal development plan is a practical leadership response because it addresses the root cause: the CISO's own reactions and interpersonal effectiveness. This is especially appropriate before a major transformation effort, where trust and cross-functional influence are critical.
- B. Incorrect.
Incorrect. Delegating executive engagement because of discomfort may temporarily reduce conflict, but it does not address the CISO's underlying leadership gap. Reorganizing the team too early can also create instability and signal avoidance rather than growth. The misconception is that technical representation can substitute for executive leadership; however, the CISO remains accountable for influencing senior stakeholders and articulating business-aligned risk decisions.
- C. Incorrect.
Incorrect. Tightening governance standards may reinforce the perception that security is rigid and uncollaborative. While governance is important, it is not the best first step when the key issue is the CISO's personal leadership effectiveness and defensive behavior. This option reflects a common mistake: using policy or authority to compensate for a lack of trust, self-awareness, or relationship management.
- D. Incorrect.
Incorrect. Waiting to engage until the roadmap is perfect delays relationship repair and may worsen executive skepticism. Senior leaders often evaluate a CISO not only on the quality of plans, but also on transparency, adaptability, and communication style. The misconception here is that more analysis alone will solve an interpersonal credibility problem; in reality, leadership effectiveness requires earlier self-correction and stakeholder engagement.