712-50 Question 177
Single answerCourage of Your ConvictionsA newly appointed CISO discovers that the company’s fastest-growing business unit is bypassing the formal vendor risk process to onboard an AI-based customer analytics platform. The CEO supports the rollout because it is tied to quarterly revenue targets, and the business unit leader argues that delaying launch would hurt competitiveness. Your team’s assessment shows unresolved issues: customer data may be transferred across jurisdictions without clear contractual safeguards, logging is insufficient for incident investigation, and the vendor has not committed to breach notification timelines. The CEO asks you to "be pragmatic" and sign off temporarily until contracts can be updated later. In demonstrating courage of conviction as a security executive, what is the BEST course of action?
- A
Approve the rollout verbally, document your concerns in an email, and rely on the business unit to remediate the issues after launch
- B
Refuse to sign off, present the specific business, legal, and incident response risks in risk language to the CEO and executive committee, and require formal risk acceptance by the appropriate authority if the rollout is to proceed
- C
Escalate directly to the board audit committee immediately without first attempting to resolve the matter through executive management channels
- D
Allow a limited production launch because revenue-generating systems can be addressed under compensating controls later, even if those controls are not yet defined
Show answer and explanation
Correct answer: B
Explanation
The best answer is Option 2 because courage of conviction for a CISO is not about being inflexible; it is about standing by sound risk management principles under pressure, communicating clearly in business terms, and ensuring accountability for risk decisions. In this scenario, the issues are not minor technical gaps. They include cross-jurisdictional data handling, inadequate logging for investigations, and missing breach notification commitments, all of which create legal, operational, and reputational exposure. Best practice in executive security governance is for the CISO to advise, quantify, and recommend, while the business owner or appropriate executive authority formally accepts residual risk if they choose to proceed. This aligns with established governance principles reflected in frameworks such as NIST Cybersecurity Framework 2.0 governance outcomes, ISO/IEC 27001 risk treatment and accountability concepts, and common third-party risk management practices. The key leadership behavior being tested is the ability to resist informal pressure, frame the issue in terms executives understand, and uphold decision rights and governance processes even when revenue pressure is high.
- A. Incorrect.
This is incorrect because merely documenting concerns after approving the rollout does not demonstrate effective security leadership or proper governance. If the CISO believes material risks remain unresolved, approving anyway shifts the posture from informed governance to passive acquiescence. A common misconception is that email documentation alone sufficiently protects the organization or the CISO. In reality, unresolved legal, privacy, and incident response deficiencies require either remediation before launch or explicit, accountable risk acceptance by the designated business authority.
- B. Correct.
This is correct because it balances courage, governance, and business alignment. Courage of conviction at the CISO level means clearly articulating risk despite executive pressure, translating technical issues into business impact, and insisting that risk decisions be made by the proper authority. The CISO should not silently absorb business risk on behalf of leadership. Requiring formal risk acceptance preserves accountability, supports informed decision-making, and demonstrates principled leadership without being obstructive for its own sake.
- C. Incorrect.
This is incorrect because immediate escalation to the board may be premature unless management refuses to address a material risk appropriately or governance channels have failed. A CISO should first engage the CEO and executive committee using established escalation paths. The misconception here is that courage means going to the highest authority first. In practice, effective executive leadership means using proportional escalation and preserving governance discipline while ensuring significant unresolved risks are visible at the right level.
- D. Incorrect.
This is incorrect because compensating controls must be specific, implemented, and validated to reduce risk meaningfully. Allowing production use based on undefined future controls is not sound risk management. This option is tempting because it appears business-friendly, but it undermines security governance and incident readiness, particularly where data transfers, contractual protections, and breach notification obligations are unclear.