712-50 Question 204
Select 3A newly appointed CISO is preparing a 12-month program to improve information systems controls across a company that has grown through acquisition. The environment includes multiple operating systems, legacy databases, several business-critical applications, and inconsistent network segmentation. Internal audit recently reported that control failures are caused less by missing policies and more by poor implementation and weak sustainment of controls. Budget is limited, so the CISO must prioritize the resources that will most effectively support implementation and ongoing maintenance of security controls. Which THREE resource decisions should the CISO prioritize first?
- A
Establish a cross-functional control ownership model with named system owners, security architects, platform administrators, and database/application support leads accountable for control operation and maintenance
- B
Acquire an additional governance, risk, and compliance (GRC) tool before validating whether current asset inventories, architecture diagrams, and system-to-data mappings are accurate and complete
- C
Build and maintain a current enterprise asset and architecture baseline, including platforms, operating systems, network zones, databases, applications, and data flows, to align controls to actual technology dependencies
- D
Allocate funding for lifecycle sustainment resources such as patching capacity, secure configuration management, vulnerability remediation, logging/monitoring support, and control testing for critical systems
- E
Defer infrastructure rationalization and standardization efforts because control effectiveness depends primarily on policy quality rather than platform diversity
Show answer and explanation
Correct answers: A, C, D
Explanation
The best answer is to prioritize resources across three categories: human capital/accountability, accurate information about the environment, and operational infrastructure/support capacity. CCISO-level decision-making requires selecting resources that make controls executable and sustainable, not merely documented. In this scenario, the audit finding points to implementation and sustainment weaknesses, so the CISO should first ensure that accountable personnel are assigned, that the enterprise has a trustworthy asset and architecture baseline, and that budget supports ongoing technical operations such as patching, hardening, remediation, logging, and testing. These decisions are consistent with established practices in frameworks such as NIST Cybersecurity Framework 2.0 (governance, asset management, and continuous improvement), NIST SP 800-53 Rev. 5 (control families requiring assigned roles, configuration management, vulnerability management, audit logging, and system maintenance), ISO/IEC 27001 and 27002 (asset management, operations security, and roles/responsibilities), and CIS Controls (inventory, secure configuration, vulnerability management, audit logs, and service provider/application management). A tool-first approach without accurate inventory and architecture data is a frequent executive mistake, and ignoring standardization increases complexity, cost, and the likelihood of inconsistent control coverage.
- A. Correct.
Correct. Effective control implementation and maintenance require clearly assigned human capital and accountability. In a heterogeneous environment, controls often fail when ownership is diffuse across infrastructure, application, and database teams. Naming responsible owners for operation, exception handling, evidence collection, and remediation supports the governance principle of accountability and aligns with common control frameworks that emphasize assigned responsibility for control execution.
- B. Incorrect.
Incorrect. A GRC platform can help organize control documentation and workflows, but it does not compensate for inaccurate foundational information about the environment. If asset inventories, architecture views, and data mappings are incomplete, the organization may implement controls in the wrong places or miss critical systems entirely. This option reflects a common misconception that tooling should precede understanding of the control environment.
- C. Correct.
Correct. Reliable information about the technology environment is a prerequisite for selecting and implementing appropriate controls. In a post-acquisition environment, undocumented platforms, unsupported operating systems, unknown data flows, and inconsistent network boundaries create control gaps. A current baseline of assets and architecture enables risk-based prioritization, identification of inherited versus compensating controls, and alignment of security requirements to real infrastructure and application dependencies.
- D. Correct.
Correct. Controls fail operationally when organizations fund projects but not sustainment. Patch management, secure configuration, vulnerability remediation, logging, monitoring, and periodic control testing are core operational resources needed to keep controls effective over time. This addresses both implementation and maintenance, especially in complex environments where technical debt and staffing constraints degrade control performance.
- E. Incorrect.
Incorrect. Standardization and rationalization usually improve control consistency, reduce administrative overhead, and simplify monitoring, hardening, and patching. While policy quality matters, platform diversity materially affects the cost and feasibility of implementing and sustaining controls. Deferring rationalization in a fragmented environment can prolong gaps and increase resource strain.