712-50 Question 192
Single answerPersonal Development PlanningA newly appointed CISO has identified that the security leadership team is strong in technical operations but weak in business communication, succession readiness, and executive influence. The board has asked for a 12-month personal development plan for the director-level security managers that demonstrates measurable improvement and supports the organization's long-term strategy. Which action should the CISO take FIRST to build an effective personal development planning program?
- A
Assign the same advanced cybersecurity certification goal to all director-level managers so progress can be compared consistently
- B
Conduct a role-based competency and gap assessment aligned to business objectives, leadership expectations, and future succession needs
- C
Require each manager to attend external leadership training immediately to address the board's concerns quickly
- D
Base each manager's development plan primarily on the weaknesses identified during the most recent annual performance review
Show answer and explanation
Correct answer: B
Explanation
In CCISO-level practice, personal development planning should be business-aligned, forward-looking, and measurable. The strongest first step is to conduct a competency and gap assessment tied to the organization's strategic direction, the security function's maturity goals, and the leadership capabilities needed for succession and executive engagement. This reflects widely accepted talent management and leadership development practices: assess current state, define target competencies, identify gaps, and then choose interventions such as coaching, mentoring, stretch assignments, formal training, and certifications. Frameworks and guidance from sources such as NIST's NICE Workforce Framework, ISACA/COBIT governance principles, and broader HR talent management best practices support role-based competency mapping and development aligned to organizational objectives. The key principle is that development plans should not start with a generic course or credential; they should start with a structured assessment of what capabilities the business needs from its security leaders.
- A. Incorrect.
This is incorrect because applying a single certification goal to all leaders does not account for individual role requirements, business context, or differing development gaps. Certifications can support development, but a personal development plan for senior security leaders should be tailored to competencies such as strategic alignment, financial acumen, communication, governance, and people leadership. Standardizing the same target for everyone is easier administratively, but it is not the best first step.
- B. Correct.
This is correct because effective personal development planning begins with understanding the competencies required for current and future leadership roles, then identifying gaps against those expectations. For a CISO, this means aligning development to enterprise strategy, board expectations, succession planning, and measurable business outcomes. A role-based assessment provides the foundation for individualized plans, targeted learning interventions, mentoring, coaching, and objective progress measures.
- C. Incorrect.
This is incorrect because training may be part of the solution, but sending all managers to training before assessing their needs is premature and may waste budget or fail to address the actual gaps. Executive leadership development should be based on validated needs rather than urgency alone. A common mistake is to confuse activity with improvement; training without diagnosis does not create a sound development program.
- D. Incorrect.
This is incorrect because annual performance reviews can provide useful input, but they are usually backward-looking and may focus on current performance rather than future capabilities. Personal development planning for security leaders should incorporate strategic role requirements, emerging business needs, and succession considerations, not just historical weaknesses documented in a performance cycle. Relying primarily on the review can create an incomplete and overly narrow plan.