712-50 Question 2
Single answerDomain 1: Governance, Risk, Compliance, and Audit Management (15%)A newly appointed CISO at a multinational financial services company is preparing for the annual board risk committee meeting. Internal audit recently reported that several business units are accepting cyber risks inconsistently, with some risks remaining open far beyond target dates and without documented business owner approval. At the same time, regulators have increased scrutiny of operational resilience and governance oversight. The CISO wants to implement a governance improvement that will both strengthen accountability and provide the board with meaningful oversight of cyber risk treatment decisions. Which action is the BEST next step?
- A
Require the security team to close all high-risk findings within 30 days, regardless of business impact, and report exceptions only to IT management
- B
Establish a formal risk acceptance process with defined approval authority, risk criteria, expiration dates, and periodic review, then report aggregated risk acceptance trends to the board
- C
Transfer ownership of all cyber risks to internal audit so that overdue remediation items can be escalated independently of business management
- D
Focus board reporting on the total number of vulnerabilities discovered each quarter, since technical volume metrics provide the clearest governance insight
Show answer and explanation
Correct answer: B
Explanation
In CCISO Domain 1, governance, risk, compliance, and audit management require clear accountability structures, risk treatment governance, and effective reporting to executive leadership and the board. In this scenario, the problem is not merely overdue remediation; it is the absence of a disciplined, business-owned risk acceptance framework. Best practice is to establish formal risk acceptance criteria, approval thresholds, review intervals, and expiration dates, ensuring residual risk is consciously accepted by the appropriate business authority rather than informally tolerated.
This approach aligns with widely recognized governance principles found in frameworks and standards such as ISO/IEC 27001 and ISO/IEC 27005 for risk management, NIST Cybersecurity Framework governance expectations, and the Three Lines Model, where management owns risk and internal audit provides independent assurance. It also supports board oversight expectations commonly reflected in regulatory guidance for financial institutions, where directors are expected to oversee risk appetite, resilience, and management accountability. The strongest governance improvement, therefore, is not to impose blanket remediation deadlines or shift ownership to audit, but to formalize risk acceptance and elevate meaningful trend reporting to the board.
- A. Incorrect.
This is not the best answer because it emphasizes forced remediation timelines without regard to business context or risk-based decision-making. Effective governance requires that risk treatment options include mitigation, transfer, avoidance, or acceptance based on business impact and risk appetite. Reporting exceptions only to IT management also weakens enterprise accountability because business owners, not just IT, must own and formally accept residual risk when remediation is not feasible within target timeframes.
- B. Correct.
This is the best answer because it addresses the core governance failure: inconsistent and undocumented risk acceptance. A formal risk acceptance process should define who can approve acceptance based on risk severity, how acceptance aligns with enterprise risk appetite and tolerance, how long acceptance remains valid, and how it is periodically reviewed or renewed. Reporting aggregate trends to the board provides oversight into whether cyber risks are being managed within approved parameters and whether exceptions are increasing, aging, or concentrating in certain business units. This supports board-level governance and regulator expectations for accountability and resilience oversight.
- C. Incorrect.
This is incorrect because internal audit should provide independent assurance, not assume management ownership of operational risks. Risk ownership belongs to the business or process owner, with the CISO facilitating visibility and governance. If internal audit becomes the owner of cyber risks, its independence is compromised. Audit should assess whether controls and risk management processes are effective, not manage remediation accountability.
- D. Incorrect.
This is incorrect because raw vulnerability counts are operational metrics, not strong governance indicators by themselves. They may reflect scanning scope or tooling maturity rather than actual risk treatment effectiveness. Boards need decision-oriented metrics tied to business risk, such as overdue high-risk issues, risk acceptance aging, concentration of accepted risks by critical process, and exposure relative to risk appetite. Technical volume metrics alone rarely provide sufficient governance insight.