712-50 Question 170
Single answerLeading with Contextual CommunicationA newly appointed CISO is preparing to brief three stakeholder groups on the same issue: a rise in third-party access risk identified during a recent assessment. The board wants to know whether business objectives are at risk, the CFO wants to understand budget implications, and the infrastructure team wants operational direction. The CISO has one week to gain support for a remediation program that includes stronger vendor onboarding controls, access reviews, and contract updates. Which communication approach would BEST demonstrate leading with contextual communication and increase the likelihood of executive and operational alignment?
- A
Deliver a single, technically detailed presentation to all groups to ensure message consistency and avoid conflicting interpretations
- B
Prepare tailored messages for each audience: business impact and risk appetite for the board, cost-benefit and loss exposure for the CFO, and implementation priorities and control objectives for the infrastructure team
- C
Focus the message on compliance obligations because regulatory pressure is the most persuasive theme across executive and technical audiences
- D
Ask the infrastructure team to present the remediation need to the board and CFO because they discovered the issue and can explain the technical details most accurately
Show answer and explanation
Correct answer: B
Explanation
Leading with contextual communication means adjusting the message to the audience while keeping the underlying facts and intent consistent. In senior security leadership, this is essential because different stakeholders make different decisions: boards govern risk and strategy, finance leaders allocate resources, and operational teams implement controls. A CISO who communicates in business terms to executives and in execution terms to practitioners is more likely to build support and drive outcomes. This aligns with broadly accepted governance and communication practices reflected in frameworks and guidance such as NIST Cybersecurity Framework governance-oriented communication principles, NIST SP 800-100 on information security governance responsibilities, and ISACA/COBIT guidance emphasizing stakeholder-specific reporting and alignment of security objectives with enterprise goals. The best answer therefore is the one that tailors the communication by stakeholder need rather than using a one-size-fits-all or purely compliance-driven message.
- A. Incorrect.
This is incorrect because consistency of facts is important, but contextual communication requires adapting the framing, level of detail, and decision focus to the audience. A single technical presentation often fails to address what each group needs to know to act. Board members typically need strategic risk and business impact, not implementation specifics.
- B. Correct.
This is correct because effective security leadership requires translating the same underlying issue into terms meaningful to each stakeholder. For the board, the discussion should connect third-party access risk to business objectives, risk tolerance, resilience, and governance decisions. For the CFO, it should address financial exposure, prioritization, and return on security investment. For the infrastructure team, it should provide actionable direction, control expectations, sequencing, and accountability. This approach supports alignment while preserving a consistent core message.
- C. Incorrect.
This is incorrect because compliance can be relevant, but making it the primary message for all audiences is not contextual communication. The board may care more about enterprise risk and strategic impact, the CFO about financial tradeoffs, and technical teams about execution. Over-reliance on compliance framing is a common mistake that can reduce engagement and fail to secure the right decisions.
- D. Incorrect.
This is incorrect because technical staff can provide valuable subject-matter input, but delegating executive persuasion to them is not the best leadership approach. Senior stakeholders usually expect the CISO to synthesize technical findings into business context and recommend a course of action. A technical explanation without strategic framing may create confusion or fail to obtain sponsorship.