712-50 Question 197
Single answerDomain 3: Information Security Controls, Security Program Management & Operations (12%)A newly appointed CISO inherits a security program at a global manufacturing company with 20 plants and a small central security team. Recent internal audit findings show that plants are implementing security controls inconsistently: some sites have strong privileged access management and logging, while others rely on shared administrator accounts and retain logs for only a few days. The board has approved funding for improvement but wants measurable risk reduction within 12 months without disrupting plant operations. Which action should the CISO take FIRST to improve security program management and operational consistency across all sites?
- A
Deploy the same technical security stack to every plant immediately, starting with the sites that have the weakest controls
- B
Establish a baseline control framework with mandatory minimum control requirements, assign control owners, and implement a risk-based exception process for plants that cannot meet the baseline immediately
- C
Outsource plant security operations to a managed security service provider so that monitoring and administration are centralized under a single contract
- D
Require each plant manager to select security controls independently based on local operational needs and report progress quarterly
Show answer and explanation
Correct answer: B
Explanation
In CCISO Domain 3, leaders are expected to manage security controls as part of an enterprise security program, not merely deploy tools. When audit identifies inconsistent implementation across business units, the first priority is to establish governance: define baseline control requirements, clarify ownership, and create a structured exception process tied to risk acceptance. This enables the organization to standardize the minimum acceptable security posture while still accommodating operational realities, especially in manufacturing or OT-influenced environments where abrupt change can affect uptime and safety. This approach is consistent with widely accepted practices reflected in frameworks such as NIST Cybersecurity Framework, NIST SP 800-53 control baselines and tailoring concepts, ISO/IEC 27001 and 27002 control governance principles, and CIS Controls implementation planning. The board's request for measurable risk reduction within 12 months is best served by a risk-based baseline program because it supports prioritization, metrics, accountability, and phased implementation rather than ad hoc technology deployment.
- A. Incorrect.
This is not the best first action. Standardizing tooling may eventually be useful, but immediately deploying the same technical stack everywhere assumes that all plants have identical operational constraints, asset types, network architectures, and risk profiles. In industrial and manufacturing environments, abrupt rollout of controls can create operational disruption and may not address underlying governance gaps such as unclear ownership, inconsistent minimum standards, and unmanaged exceptions. A CISO should first define what controls are required and how they will be governed before enforcing specific technologies.
- B. Correct.
This is the best answer. Inconsistent control implementation across distributed sites is primarily a governance and program management problem. Establishing a baseline control framework creates a minimum required security posture across all plants, while assigning control owners ensures accountability for implementation and operation. A formal risk-based exception process allows business-critical plants to document temporary deviations without undermining the overall program. This approach supports measurable improvement, enables prioritization, and aligns with common practices in security governance, control standardization, and operational risk management.
- C. Incorrect.
This may help with certain operational activities, but it is not the best first step. A managed service provider can centralize monitoring, but outsourcing does not by itself resolve inconsistent control expectations, weak privileged access practices, or lack of governance. Without defined baseline requirements and ownership, the provider would inherit the same ambiguity. This option reflects a common misconception that centralization alone fixes control design and accountability issues.
- D. Incorrect.
This is incorrect because it reinforces the inconsistency already identified by audit. Allowing each plant to select controls independently may accommodate local needs, but without centrally defined minimum requirements it leads to uneven risk treatment, poor comparability across sites, and difficulty demonstrating enterprise-level control maturity to the board. Quarterly reporting is useful, but reporting on nonstandardized controls does not create an effective security program.