712-50 exam dumps

712-50 practice question 214 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 214

Single answerSecurity Program Management (6 questions)

A newly appointed CISO is consolidating security activities across three business units after a merger. Each unit has different risk tolerances, duplicated tools, and inconsistent policies. The CEO has asked for a single enterprise security program that improves risk visibility, supports business growth, and demonstrates measurable value to executive leadership. The CISO has limited budget for the first year and expects resistance from unit leaders who do not want to lose autonomy. Which action should the CISO take FIRST to establish an effective security program management foundation?

  1. A

    Standardize all security tools and retire duplicate platforms immediately to reduce cost and simplify administration

  2. B

    Develop an enterprise security strategy aligned to business objectives, define governance and risk accountability, and establish a prioritized roadmap based on enterprise risk

  3. C

    Mandate a single set of enterprise security policies for all business units and require compliance sign-off from each unit head within 30 days

  4. D

    Launch a security awareness campaign for all employees to create a common security culture before making structural changes

Show answer and explanation

Correct answer: B

Explanation

Security program management at the executive level begins with business alignment, governance, and risk-based planning. In a merged organization, the CISO must first understand the enterprise mission, strategic objectives, legal and regulatory obligations, and differing business unit risk profiles. From there, the CISO should define governance structures, clarify decision rights and accountability, and produce a prioritized roadmap that sequences policy harmonization, control improvements, metrics, and technology rationalization.

This approach is consistent with widely accepted practices in security governance and program management, including ISACA COBIT principles on governance and alignment, NIST Cybersecurity Framework guidance on aligning cybersecurity outcomes to organizational needs, and ISO/IEC 27001 concepts around establishing, implementing, maintaining, and continually improving an information security management system. Executive leadership typically expects the CISO to demonstrate measurable value through risk reduction, business enablement, and transparent governance rather than isolated technical changes. Therefore, the most appropriate first action is to build the enterprise security strategy and governance foundation before driving tactical standardization efforts.

  • A. Incorrect.

    This is not the best first step. Tool rationalization may eventually be appropriate, but immediately standardizing platforms without first understanding business priorities, risk appetite, regulatory requirements, and governance structure can disrupt operations and create resistance. In security program management, technology consolidation should follow strategy, governance, and risk-based prioritization rather than precede them.

  • B. Correct.

    This is correct. In a post-merger environment, the CISO should first create an enterprise security strategy tied to business objectives and establish governance, roles, and accountability. A risk-based roadmap allows the organization to prioritize investments, sequence policy harmonization, and rationalize tools in a way that supports business goals and manages stakeholder resistance. This approach reflects core CCISO expectations for security program management: alignment with the enterprise, governance definition, and measurable planning.

  • C. Incorrect.

    This is a plausible but premature response. Policy harmonization is important, but mandating immediate uniformity before establishing governance, understanding business differences, and obtaining executive alignment can lead to superficial compliance and pushback. A policy program is one component of a broader security program and should be informed by enterprise strategy and risk management decisions.

  • D. Incorrect.

    Security awareness has value, but it does not establish the foundational structure of an enterprise security program. Awareness campaigns are supporting activities, not the first action needed to unify governance, define risk ownership, or build a strategic roadmap. Starting here may improve messaging but will not resolve duplicated controls, inconsistent accountability, or competing business priorities.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam