712-50 exam dumps

712-50 practice question 215 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 215

Single answerSecurity Program Management (6 questions)

A newly appointed CISO inherits a fragmented security environment after a merger. The acquired business unit uses different policies, tools, and reporting metrics, and business leaders are pressuring the CISO to quickly standardize controls across both organizations. However, the CISO's budget for the current year is fixed, several critical customer-facing projects are underway, and internal audit has noted inconsistent risk treatment decisions between the two legacy organizations. To establish an effective enterprise security program without disrupting key business operations, what should the CISO do FIRST?

  1. A

    Mandate immediate adoption of a single set of security tools and policies across both organizations to eliminate inconsistency

  2. B

    Perform an enterprise-wide security and risk program assessment, map current-state controls and governance processes, and define a prioritized integration roadmap aligned to business risk

  3. C

    Delay any integration activity until the next budget cycle so that a fully funded transformation program can be launched

  4. D

    Focus first on replacing the acquired company's security leadership and operational staff to ensure consistent execution of the target security model

Show answer and explanation

Correct answer: B

Explanation

In CCISO-level security program management, the CISO is expected to build and mature an enterprise program through governance, prioritization, and business alignment rather than by reacting tactically. In a post-merger scenario, the most appropriate first action is to assess the current state across both organizations and create a risk-based integration roadmap. This allows the CISO to identify overlapping controls, critical gaps, inconsistent risk treatment decisions, and dependencies tied to customer-facing operations. It also supports defensible budget allocation and executive communication. This approach aligns with widely accepted practices in governance and risk management, including NIST Cybersecurity Framework guidance on assessing current and target states, ISO/IEC 27001 concepts for establishing and maintaining an information security management system, and audit/governance expectations that risk treatment decisions be consistent, documented, and tied to business objectives. The key principle is that enterprise security programs should be integrated through governance and risk-based planning first, with tooling and structural changes following from that analysis.

  • A. Incorrect.

    This is incorrect because forcing immediate standardization without first understanding current-state risks, business dependencies, control gaps, and governance differences can disrupt operations and misallocate limited resources. In security program management, the first step should be to assess the environment and prioritize based on enterprise risk and business impact. A tool- or policy-first approach is a common mistake when integrating after a merger.

  • B. Correct.

    This is correct because a CISO should first establish a fact-based view of the combined security posture, including governance, policies, controls, reporting, risk treatment practices, and business priorities. A structured assessment enables rational prioritization, supports budget-constrained decision-making, and creates a roadmap for integrating the security program in a way that aligns with business objectives. This approach also addresses audit concerns about inconsistent risk treatment by introducing common governance and decision criteria before broad operational changes are imposed.

  • C. Incorrect.

    This is incorrect because deferring action entirely until the next budget cycle leaves known inconsistencies in governance and risk treatment unresolved. While the budget is fixed, the CISO can still perform assessment, governance alignment, prioritization, and targeted remediation planning. Effective security program management requires progress within constraints rather than postponing all action.

  • D. Incorrect.

    This is incorrect because personnel changes do not address the core issue first: the organization lacks a unified understanding of current controls, risks, governance practices, and business priorities. Replacing leaders or staff prematurely can create additional instability and may be unjustified if the real problem is inconsistent program structure rather than poor individual performance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam