712-50 exam dumps

712-50 practice question 198 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 198

Single answerInformation Security Management Controls (6 questions)

A newly appointed CISO at a global manufacturing company discovers that business units have implemented security controls independently over several years. As a result, there are duplicate tools, inconsistent control ownership, and gaps in monitoring for third-party access. The board has asked the CISO to improve governance and demonstrate that security controls are aligned to business risk, regulatory obligations, and operational accountability without causing major disruption to production. Which action should the CISO take FIRST to establish effective information security management controls?

  1. A

    Mandate a single enterprise security toolset immediately and retire all overlapping controls within one quarter

  2. B

    Perform a control rationalization and mapping exercise to align existing controls with business processes, risk scenarios, compliance requirements, and accountable control owners

  3. C

    Increase the frequency of vulnerability scanning across all sites and require weekly reporting to the board

  4. D

    Outsource third-party access monitoring to a managed security service provider to close the most visible gap quickly

Show answer and explanation

Correct answer: B

Explanation

The best first step is to understand and organize the control environment through control rationalization and mapping. In a fragmented environment, the CISO must first determine which controls exist, what risks and obligations they address, who owns them, and how effectively they operate. This is a core information security management control activity because it establishes governance, accountability, and alignment with enterprise risk management before major technology or sourcing decisions are made. Once that baseline exists, the organization can prioritize consolidation, remediation, automation, and monitoring improvements with less operational risk.

This approach aligns with widely accepted practices in frameworks such as ISO/IEC 27001 and ISO/IEC 27002, which emphasize risk-based control selection, ownership, and periodic review; NIST SP 800-53, which organizes controls around governance, assessment, and accountability; and COBIT, which stresses control objectives, process ownership, and alignment with business goals. For a CCISO-level leader, the key is not simply deploying more controls, but ensuring that management controls are governed, mapped to risk and compliance requirements, and owned by accountable stakeholders.

  • A. Incorrect.

    This is incorrect because forcing rapid standardization of tools before understanding current control coverage, ownership, business dependencies, and risk impact can create operational disruption and leave unrecognized gaps. Tool consolidation may eventually be appropriate, but it should follow a governance-led assessment of what controls exist, what risks they mitigate, and where accountability resides. A common misconception is that control effectiveness is primarily a tooling problem; in reality, information security management controls start with governance, risk alignment, and clearly assigned responsibilities.

  • B. Correct.

    This is correct because the first priority is to establish a structured view of the current control environment and align it to business objectives, risk appetite, regulatory requirements, and ownership. A control rationalization and mapping exercise helps identify redundant, missing, or ineffective controls and clarifies who is accountable for operating and monitoring them. This creates the foundation for governance decisions, targeted remediation, reporting, and future optimization with minimal unnecessary disruption. It also supports a risk-based approach rather than reacting to symptoms.

  • C. Incorrect.

    This is incorrect because increasing vulnerability scanning addresses only one technical control area and does not solve the broader management control issues of duplication, inconsistent ownership, governance misalignment, and third-party oversight. Weekly board reporting on a narrow operational metric may create noise rather than meaningful governance insight. Candidates may choose this option because scanning is tangible and measurable, but it is too tactical for the stated problem.

  • D. Incorrect.

    This is incorrect because outsourcing monitoring for third-party access may help with one identified gap, but it does not first establish whether the control is appropriate, how it integrates with internal accountability, or how it fits into the broader control framework. Managed services can support operations, but they do not replace the CISO's responsibility to define governance, ownership, and risk-based control objectives. This option is attractive because it appears fast, but it treats a symptom rather than the root cause.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam