712-50 Question 180
Single answerAdaptability, Resilience, and AgilityA global manufacturing company is accelerating digital transformation by moving several plant operations and supplier integrations to cloud-based platforms. Recent disruptions, including a ransomware incident at a regional supplier and an unexpected outage in a shared SaaS platform, exposed that the security program is heavily dependent on annual risk reviews, static controls, and slow exception handling. The CEO asks the CISO to improve the organization's adaptability, resilience, and agility without significantly delaying business initiatives. Which action should the CISO prioritize FIRST to achieve this objective at the enterprise level?
- A
Implement a continuous, risk-based security governance model that includes updated business impact criteria, defined resilience requirements for critical services, and regular cross-functional decision cycles for emerging threats and business changes
- B
Mandate immediate deployment of the same security control baseline across all plants, suppliers, and cloud services to reduce architectural variation and simplify oversight
- C
Increase the frequency of enterprise penetration tests from annually to quarterly and use the results as the primary driver for resilience improvements
- D
Require all new digital initiatives to be approved by the security architecture team only after a full set of preventive controls is implemented with no temporary risk acceptance
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because adaptability, resilience, and agility at the CCISO level are primarily leadership and governance outcomes, not just technology outcomes. In this scenario, the organization has already demonstrated that static annual reviews and slow exception handling are inadequate for a changing threat and business landscape. The CISO should first establish a continuous, risk-based governance model that integrates business impact, service criticality, resilience requirements, and recurring cross-functional review. This enables the enterprise to adjust security priorities as business models, suppliers, technologies, and threats evolve.
This approach aligns with widely accepted security and resilience practices. NIST Cybersecurity Framework 2.0 emphasizes governance, risk management, and continuous improvement across changing business contexts. NIST SP 800-39 highlights ongoing risk management at the organizational level, not just periodic assessment. NIST SP 800-61 and broader incident response guidance reinforce the need for coordinated, repeatable decision-making across stakeholders. ISO/IEC 27001 and ISO 22301 also support risk-based management systems, business continuity, and resilience planning tied to critical services and recovery priorities.
At the executive level, the CISO should ensure that security is embedded into business change processes, supplier risk oversight, cloud adoption, and operational resilience decision-making. Once this governance foundation is in place, technical baselines, testing cadence, and control enforcement can be tailored more effectively to support both business velocity and resilience.
- A. Correct.
Correct. This option addresses the root problem: the organization relies on static, periodic security management in a dynamic environment. A continuous, risk-based governance model helps the CISO align security decisions with changing business conditions, threat intelligence, operational dependencies, and resilience objectives. Including business impact criteria and resilience requirements ensures that critical processes are identified and protected according to recovery needs, while regular cross-functional decision cycles improve agility by enabling timely risk treatment, exception handling, and adaptation. This is the strongest enterprise-level first step because it establishes the operating model needed to make later control decisions effective and responsive.
- B. Incorrect.
Incorrect. Standardization can improve manageability in some areas, but forcing the same baseline across highly diverse environments such as plants, suppliers, and cloud services can reduce adaptability and ignore differences in operational technology, contractual constraints, threat exposure, and business criticality. A one-size-fits-all baseline may create either overcontrol or underprotection. The misconception is that uniformity automatically produces resilience; in practice, resilience depends on context-aware controls and governance that can adapt to varying risk profiles.
- C. Incorrect.
Incorrect. More frequent penetration testing may provide useful technical findings, but it does not by itself create organizational agility or resilience. Penetration testing is a point-in-time assessment and is not a substitute for continuous governance, business impact analysis, service resilience planning, or adaptive decision-making. A candidate might choose this because testing sounds proactive, but relying on it as the primary driver overlooks the management and operational processes necessary to respond to changing risks and disruptions.
- D. Incorrect.
Incorrect. Requiring full preventive controls before any approval may slow delivery and conflict with the CEO's requirement not to significantly delay business initiatives. Modern security leadership balances risk, resilience, and business speed through informed risk acceptance, compensating controls, phased remediation, and governance mechanisms. The misconception here is that agility is achieved through stricter gatekeeping; in reality, excessive central approval and zero-tolerance for temporary risk can reduce organizational responsiveness and encourage shadow IT or business workarounds.