712-50 Question 183
Single answerUsing Time and Priorities DecisionsA newly appointed CISO at a global manufacturing company is preparing the security program for the next two quarters. The board has mandated measurable reduction in business risk within six months, while the security team is understaffed and already committed to a major identity modernization project. At the same time, a recent internal audit identified weak third-party access controls, several medium-severity vulnerabilities on legacy OT-connected systems, and inconsistent incident response tabletop testing. The CISO must decide how to use limited leadership time, funding, and staff attention. Which action is the BEST example of using time and priorities decisions at the executive level?
- A
Pause the identity modernization project and direct the team to remediate every audit finding immediately so no known issue remains open at the next audit review
- B
Prioritize initiatives by business impact and urgency, assign executive attention first to third-party access controls and incident response readiness, and defer lower-risk remediation through a documented, risk-accepted roadmap
- C
Split funding and staff evenly across all identified issues so each area shows progress and no stakeholder feels deprioritized
- D
Focus the next two quarters primarily on medium-severity OT vulnerabilities because technical weaknesses should be addressed before governance and response process improvements
Show answer and explanation
Correct answer: B
Explanation
The best answer is the option that applies risk-based prioritization under time and resource constraints. A CCISO-level leader is expected to make portfolio decisions that maximize business risk reduction, not simply react to audits, divide resources evenly, or focus only on technical remediation. In practice, this means evaluating initiatives by factors such as business criticality, threat exposure, time sensitivity, dependency on strategic programs, regulatory implications, and the organization's capacity to execute. Prioritizing third-party access controls and incident response readiness is defensible because supplier access is a common attack vector and response preparedness reduces the impact of inevitable incidents. Deferring lower-priority work through a documented plan with formal risk treatment is consistent with governance best practices seen in frameworks such as NIST Cybersecurity Framework, NIST SP 800-39 risk management principles, ISO/IEC 27005 risk treatment concepts, and general enterprise risk management approaches. The key leadership skill being tested is the ability to use limited time and attention on the highest-value decisions rather than trying to do everything at once.
- A. Incorrect.
This is incorrect because it reflects an audit-driven rather than risk-driven prioritization model. While audit findings matter, a CISO should not automatically stop strategic initiatives and attempt to close every issue immediately without considering business impact, resource constraints, risk treatment options, and expected risk reduction. This approach often causes disruption, burns leadership time on lower-value work, and ignores the reality that some risks are better managed through phased remediation and formal acceptance.
- B. Correct.
This is correct because it demonstrates executive prioritization based on business risk, time sensitivity, and achievable outcomes within constrained resources. Third-party access weaknesses can create high-likelihood pathways for compromise, and incident response readiness directly affects organizational resilience and loss reduction. Deferring lower-risk items through a documented roadmap with appropriate risk acceptance is consistent with effective security governance, portfolio management, and the CISO's role in aligning effort to the most material business outcomes within a defined time horizon.
- C. Incorrect.
This is incorrect because equal distribution of resources is usually a poor prioritization method when risks are not equal. It may appear politically balanced, but it does not optimize for risk reduction, strategic objectives, or time-to-value. Executive-level time and priority decisions require deliberate trade-offs, not uniform allocation designed mainly to satisfy stakeholders.
- D. Incorrect.
This is incorrect because it overemphasizes one class of technical issues without considering relative business impact, exploitability, compensating controls, response capability, or the board's six-month risk reduction mandate. Medium-severity vulnerabilities on legacy OT-connected systems may deserve attention, but governance and response gaps can represent broader enterprise exposure and can often be improved more quickly with stronger near-term risk reduction.