712-50 exam dumps

712-50 practice question 184 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 184

Single answerNegotiation, Mediation, and Alternative Conflict Resolution

A newly appointed CISO is trying to resolve a conflict between the security architecture team and the product development leadership. Security wants mandatory secure design reviews before release because several recent findings involved exposed APIs. Product leadership argues that the additional review gate will cause missed customer commitments and revenue delays. The CEO has asked the CISO to resolve the issue quickly without damaging cross-functional relationships. Which action should the CISO take FIRST to achieve the most sustainable resolution?

  1. A

    Escalate the dispute to the CEO and request a directive requiring all releases to pass security review before deployment

  2. B

    Facilitate an interest-based negotiation session with both groups to identify underlying business and risk concerns, then propose a risk-based review model

  3. C

    Have the security team document all technical objections and send them to legal so legal can determine which side has the stronger position

  4. D

    Allow product leadership to decide release timing independently, but require the security team to log formal exceptions after deployment

Show answer and explanation

Correct answer: B

Explanation

The scenario tests the CCISO's ability to use negotiation and alternative conflict resolution to resolve a cross-functional governance dispute. The strongest first step is an interest-based negotiation or mediated discussion that clarifies each party's objectives, constraints, and acceptable tradeoffs. This aligns with established negotiation best practices from sources such as the Harvard Principled Negotiation model, which emphasizes separating people from the problem, focusing on interests rather than positions, generating options for mutual gain, and using objective criteria. In information security leadership, this often translates into a risk-based approach: for example, applying deeper reviews to high-risk releases, defining service-level targets for review turnaround, or introducing compensating controls for lower-risk changes. A CCISO should reserve executive escalation for situations where collaborative resolution fails, the issue exceeds delegated authority, or there is an immediate unacceptable risk. The key leadership principle is to resolve the dispute in a way that balances business enablement, risk management, and long-term stakeholder trust.

  • A. Incorrect.

    This is not the best first action. Executive escalation may impose a short-term decision, but it often hardens positions, reduces ownership, and can damage long-term working relationships. In conflict resolution, especially for peer business functions, escalation is generally more appropriate after direct negotiation or mediation efforts fail. A CCISO should first try to align business objectives and risk tolerance rather than immediately seek authority-based resolution.

  • B. Correct.

    This is the best answer. Interest-based negotiation focuses on the parties' underlying interests rather than stated positions. Here, security's interest is reducing material risk from insecure releases, while product leadership's interest is maintaining delivery commitments and revenue. A facilitated discussion can uncover options such as tiered reviews based on application criticality, release type, or risk thresholds. This approach reflects strong executive leadership because it preserves relationships, addresses root causes, and supports a practical, risk-based operating model.

  • C. Incorrect.

    This is incorrect because it reframes a business governance conflict as a legal adjudication issue. Legal input may be useful later if regulatory or contractual obligations are unclear, but legal is not the primary mechanism for resolving an operational disagreement over release governance. Choosing this path too early can polarize the conflict and shift focus away from business risk management and collaborative problem solving.

  • D. Incorrect.

    This is incorrect because it effectively bypasses preventive control governance and normalizes risk acceptance after the fact. Formal exceptions are useful when managed within a defined risk acceptance process, but allowing unilateral release decisions first undermines security governance and may create inconsistent accountability. It also fails to address the core conflict or build a sustainable resolution process.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam