712-50 Question 167
Single answerUnderstanding OthersA newly appointed CISO is leading a security transformation after several business units complained that the security team is "blocking innovation." The company is preparing to launch a digital customer platform in four months, and tensions are rising between security, product management, and operations. In the first executive steering committee meeting, the CISO notices that the product VP is focused on launch deadlines and revenue impact, the operations director is concerned about service stability, and the legal counsel is worried about regulatory exposure. Which action should the CISO take FIRST to demonstrate strong understanding of others and improve the likelihood of gaining support for the security program?
- A
Present a detailed list of critical vulnerabilities and require each executive to accept the associated risks in writing before the launch proceeds.
- B
Meet individually with each stakeholder group to understand their objectives, constraints, and success metrics, then frame security recommendations in terms of those business priorities.
- C
Escalate to the CEO that business leaders are not treating security seriously enough and request a mandate requiring all projects to follow security directives.
- D
Delay the platform launch until the security team can complete all planned controls, demonstrating that security standards take precedence over competing business interests.
Show answer and explanation
Correct answer: B
Explanation
The core competency being tested is the CISO's ability to understand others as part of executive leadership and influence. At the CCISO level, this means more than technical awareness; it requires empathy, stakeholder analysis, and the ability to communicate security in the language of business outcomes. A strong CISO first seeks to understand what matters to each stakeholder: product leaders may prioritize time-to-market and revenue, operations may prioritize availability and supportability, and legal may prioritize compliance and liability reduction. Once those drivers are understood, the CISO can tailor risk discussions and security recommendations accordingly.
This approach aligns with widely accepted leadership and governance practices, including stakeholder engagement emphasized in security governance frameworks such as ISO/IEC 27014 and business-alignment principles found in COBIT. It also reflects the NIST Cybersecurity Framework's emphasis on governance, risk-informed decision-making, and organizational context. The best initial step is therefore not to escalate, mandate, or block, but to understand stakeholder perspectives and build a shared path forward.
- A. Incorrect.
This is not the best first action. While risk acceptance can be appropriate within a formal governance process, leading with vulnerabilities and written acceptance tends to position security as adversarial rather than collaborative. It does not demonstrate empathy for stakeholder drivers such as revenue, uptime, or legal obligations, and it is unlikely to build trust early in a transformation effort.
- B. Correct.
This is correct. Understanding others in an executive leadership context means identifying stakeholder motivations, incentives, pressures, and definitions of success before attempting to influence decisions. By engaging each group individually and translating security recommendations into terms they value, such as release confidence, resilience, regulatory defensibility, and customer trust, the CISO can build alignment and reduce resistance. This approach reflects stakeholder management, active listening, and business-oriented communication expected of a senior security leader.
- C. Incorrect.
This is a plausible but ineffective response. Executive escalation may sometimes be necessary, but using it first bypasses relationship-building and can damage credibility. It signals that the CISO has not tried to understand the business context or negotiate tradeoffs. In CCISO-level leadership, influence is strongest when the CISO first seeks alignment rather than relying immediately on authority.
- D. Incorrect.
This is incorrect because it reflects a security-first, business-last mindset that often creates conflict and may be impractical. Mature security leadership balances risk with business objectives, using risk-based prioritization instead of insisting that every control be completed before progress is allowed. It also fails to account for stakeholder concerns and does not show understanding of operational or commercial realities.