712-50 Question 166
Single answerUnderstanding OthersA newly appointed CISO is leading a security transformation program after several business units complained that the security team is "blocking revenue-generating initiatives." During executive meetings, the head of Sales argues for rapid deployment of a customer-facing analytics platform, while the Operations director is concerned about service stability and the Legal counsel is focused on cross-border data handling. The CISO needs to rebuild trust and gain support for a phased security roadmap. Which action is MOST effective to demonstrate understanding of others while improving the likelihood of executive alignment?
- A
Require each executive to accept the security roadmap as written because enterprise risk decisions must ultimately follow the CISO's guidance
- B
Begin by mapping each stakeholder's objectives, constraints, and risk concerns, then tailor the roadmap discussion in business terms such as revenue impact, resilience, and regulatory exposure
- C
Present a detailed list of security control deficiencies and explain that technical remediation must be completed before any business initiative proceeds
- D
Ask the CEO to mandate compliance from the business units so that resistance does not delay the transformation program
Show answer and explanation
Correct answer: B
Explanation
The best answer is to first understand stakeholder perspectives and then communicate in terms meaningful to them. In CCISO-level leadership, "understanding others" is a core interpersonal and executive management capability: the CISO must influence across functions, not merely issue technical directives. Effective stakeholder management involves identifying each leader's business objectives, risk tolerance, incentives, constraints, and sources of pressure. This supports tailored communication and negotiation, which are essential in enterprise security governance.
This approach is consistent with widely accepted security and governance practices. For example, NIST's guidance on risk management emphasizes organizational context, stakeholder communication, and framing risk in support of mission and business objectives. Similarly, ISO/IEC 27014 and broader governance best practices stress aligning information security with organizational goals and engaging decision-makers in language they can act on. A CISO who demonstrates empathy and situational awareness is more likely to build credibility, gain sponsorship, and implement a roadmap that is both secure and business-enabling.
- A. Incorrect.
This is incorrect because it reflects a command-and-control approach rather than executive leadership through influence and understanding. In most organizations, the CISO advises on cyber risk and enables informed decision-making, but does not unilaterally compel business acceptance without considering stakeholder drivers. This approach would likely reinforce the perception that security is disconnected from business priorities.
- B. Correct.
This is correct because understanding others in a CCISO context means identifying stakeholder motivations, pressures, incentives, and constraints before attempting to persuade them. By framing the roadmap around what matters to each executive, revenue enablement for Sales, operational continuity for Operations, and compliance and liability concerns for Legal, the CISO demonstrates empathy, business acumen, and strategic communication. This increases trust and helps align security objectives with enterprise objectives.
- C. Incorrect.
This is incorrect because although identifying control gaps is important, leading with technical deficiencies does not demonstrate understanding of stakeholder perspectives. Executives typically respond better to risk translated into business impact than to raw technical detail. Someone might choose this option because remediation is necessary, but it is not the most effective first step for rebuilding trust and aligning diverse stakeholders.
- D. Incorrect.
This is incorrect because executive mandate can force short-term compliance, but it does not show that the CISO understands competing business concerns. Overreliance on escalation often damages long-term relationships and can reduce cooperation. A mature security leader should first seek alignment through dialogue, stakeholder analysis, and shared objectives before turning to authority.