712-50 Question 201
Single answerIdentify the organization's operational process and objectivesA newly appointed CISO at a global medical device manufacturer is preparing a 3-year security strategy. The company has recently expanded into direct-to-hospital digital services, and the board has asked the CISO to ensure security investments support revenue growth, regulatory obligations, and uninterrupted product delivery. Business unit leaders provide a long list of requests, including more endpoint tools, additional penetration tests, and a new SIEM. Before prioritizing controls and budget, which action should the CISO take FIRST to identify the organization's operational processes and objectives in a way that will best align the security strategy with the business?
- A
Map the organization's value streams, critical business processes, dependencies, and strategic objectives by engaging executive leadership and process owners
- B
Benchmark the security program against peer medical device companies and adopt the most common control set
- C
Begin with an enterprise-wide vulnerability assessment to determine where technical weaknesses are most severe
- D
Purchase a governance, risk, and compliance platform so business units can enter their security requirements in one system
Show answer and explanation
Correct answer: A
Explanation
In CCISO practice, the security strategy should be derived from business strategy, operating model, and critical processes rather than from a list of tools or technical findings. The first priority is to identify how the organization operates: its value streams, key products and services, supporting processes, regulatory obligations, third-party dependencies, and strategic goals. This aligns with widely accepted governance and risk management practices in frameworks such as COBIT, which emphasizes aligning IT and security-related activities with enterprise goals, and NIST guidance, which stresses understanding organizational context, mission objectives, and critical functions before selecting and prioritizing controls. Once the CISO understands the organization's operational processes and objectives, the security program can rationally prioritize capabilities such as monitoring, testing, resilience, and compliance support based on business impact rather than popularity or urgency of requests.
- A. Correct.
Correct. A CISO must first understand how the organization creates value, which operational processes are mission-critical, what strategic outcomes the business is pursuing, and which dependencies support those outcomes. Engaging executive leadership and business process owners helps identify crown-jewel processes, revenue-generating services, regulatory constraints, uptime expectations, and risk tolerance. This creates the context needed to prioritize security investments in a business-aligned manner rather than reacting to isolated control requests.
- B. Incorrect.
Incorrect. Peer benchmarking can be useful later for maturity comparisons or validating program direction, but it does not identify this specific organization's operational processes, objectives, or risk drivers. Two companies in the same sector may have very different operating models, growth strategies, regulatory exposure, and digital dependencies. Adopting common controls without understanding internal business context can misallocate resources.
- C. Incorrect.
Incorrect. A vulnerability assessment identifies technical weaknesses, but it does not establish which business processes matter most or how security should support strategic objectives such as digital service growth and product delivery continuity. Starting with vulnerabilities often drives a technology-first approach rather than a business-first strategy. Technical findings should be prioritized only after business context is understood.
- D. Incorrect.
Incorrect. A GRC platform may improve documentation and workflow, but technology acquisition is not the first step in identifying operational processes and objectives. Without first defining business priorities, process ownership, and strategic drivers, the platform may simply capture unstructured requests. Governance tooling supports the program; it does not replace foundational business analysis.