712-50 exam dumps

712-50 practice question 199 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 199

Single answerInformation Security Management Controls (6 questions)

A newly appointed CISO is reviewing the organization’s information security management controls after an internal audit found that several business units implemented security practices inconsistently. Some units perform quarterly access reviews, others do not. Change management is mature in IT operations but rarely includes security impact assessment. Policies exist, but control owners are unclear and evidence of control performance is difficult to produce during audits. The CEO has asked for a plan that improves consistency, accountability, and auditability without creating unnecessary operational overhead. Which action should the CISO take FIRST to strengthen information security management controls across the enterprise?

  1. A

    Deploy a new security monitoring platform to centrally detect control failures across all business units

  2. B

    Establish a formal control framework that maps policies to specific control objectives, assigns control ownership, and defines control testing and evidence requirements

  3. C

    Require all business units to adopt the same technical security tools and configurations immediately

  4. D

    Increase the frequency of internal audits so deficiencies are identified earlier and reported to executive management

Show answer and explanation

Correct answer: B

Explanation

The key issue in this scenario is not merely a lack of technology or insufficient audit frequency, but weak governance over information security management controls. In a mature security program, policies should cascade into clearly defined control objectives, control activities, ownership assignments, testing procedures, and evidence requirements. This supports consistency across business units while preserving flexibility for different operational contexts. Best practices from control and governance frameworks such as ISO/IEC 27001 and ISO/IEC 27002 emphasize defined responsibilities, documented controls, monitoring, and continual improvement. Similarly, governance-oriented frameworks such as COBIT stress control ownership, accountability, and assurance mechanisms. A CISO should first establish or rationalize the control framework so that audits, monitoring, and technical implementations operate against a consistent baseline. Once the framework is in place, the organization can more effectively optimize tools, increase assurance activities, and improve reporting to executive leadership.

  • A. Incorrect.

    This is not the best first step. A monitoring platform may help detect certain operational issues, but it does not solve the underlying governance problem: inconsistent control design, undefined ownership, and lack of evidence standards. Monitoring is a supporting capability, not a substitute for an established management control structure.

  • B. Correct.

    This is correct. The scenario highlights classic information security management control weaknesses: inconsistent implementation, unclear accountability, and poor audit evidence. The most effective first action is to formalize the control environment by defining control objectives, mapping them to policy requirements and business processes, assigning accountable control owners, and specifying how controls are tested and evidenced. This creates consistency, supports auditability, and enables risk-based oversight without imposing arbitrary technical standardization where it may not be appropriate.

  • C. Incorrect.

    This is a plausible but incorrect response. Standardizing tools may reduce some variation, but the problem described is broader than technology. Management controls include governance, responsibility, review processes, evidence collection, and oversight. Forcing uniform tools does not ensure that access reviews, security impact assessments, or control accountability will occur effectively.

  • D. Incorrect.

    This is not the best first action. More frequent audits may uncover issues sooner, but auditing a poorly defined control environment generally increases cost and friction without correcting the root cause. Audits should assess an established control framework; they should not be relied on as the primary mechanism to create management discipline.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam