712-50 Question 187
Single answerLeading with Problem SolvingA newly appointed CISO inherits a security program after a costly ransomware incident. The board is frustrated because the security team has responded by proposing dozens of disconnected tool purchases, while business unit leaders complain that security is slowing recovery and future product launches. The CEO asks the CISO to demonstrate leadership by solving the underlying problem rather than reacting tactically. Which action should the CISO take FIRST to lead effective problem solving at the executive level?
- A
Develop an enterprise-wide problem statement that links the incident's root causes to business risk, validate it with key stakeholders, and prioritize a small set of risk-reduction initiatives aligned to recovery and strategic objectives
- B
Approve the security team's proposed tool acquisitions so the organization can quickly show visible action to the board and reassure customers
- C
Reorganize the security department immediately, replacing incident response leadership to demonstrate accountability before assessing broader business impacts
- D
Require each business unit to submit its own security remediation plan independently, then consolidate the plans into an annual security roadmap
Show answer and explanation
Correct answer: A
Explanation
In CCISO practice, leading with problem solving means framing the issue correctly before prescribing solutions. After a major incident, senior leaders should resist the pressure to react with isolated technical purchases or symbolic restructuring. Instead, they should establish a clear problem statement, perform root-cause analysis, engage stakeholders across business and technology functions, and prioritize initiatives according to business impact and risk reduction. This aligns with widely accepted practices from NIST incident handling and risk management guidance, which emphasize analysis, prioritization, and risk-based decision-making, as well as governance principles found in frameworks such as COBIT and ISO/IEC 27001 that stress alignment between security activities and organizational objectives. The best first step is therefore to define the enterprise problem in business terms and drive a coordinated, risk-informed response.
- A. Correct.
Correct. This reflects executive-level problem solving: define the actual problem, determine root causes, connect them to enterprise risk, and align solutions to business priorities. A CCISO is expected to avoid isolated technical reactions and instead lead a structured, stakeholder-informed response that balances resilience, recovery, and strategic enablement. This approach also improves buy-in across the organization and supports defensible prioritization for the board.
- B. Incorrect.
Incorrect. Although visible action can be politically tempting after an incident, buying tools before confirming the problem often leads to duplicated controls, wasted budget, and unresolved root causes. This is a common misconception that more technology automatically equals better security. Effective leaders first identify whether the issue is governance, process, architecture, staffing, third-party risk, or control effectiveness before selecting solutions.
- C. Incorrect.
Incorrect. Accountability matters, but reorganizing or replacing leaders before understanding the full problem is premature and may be perceived as symbolic rather than strategic. It can also destabilize recovery efforts and discourage candid root-cause analysis. Executive problem solving should focus first on fact-based diagnosis and enterprise impact, not immediate structural changes designed mainly to signal decisiveness.
- D. Incorrect.
Incorrect. Business-unit input is important, but asking each unit to solve the issue independently fragments the response and often produces inconsistent priorities, duplicated effort, and uneven risk treatment. One of the CISO's leadership responsibilities is to synthesize cross-functional perspectives into an enterprise-level problem definition and coordinated plan, rather than delegating core problem framing to separate units.