712-50 Question 216
Single answerFor each information systems project develop a clear project scope statement in alignment with organizational objectivesA global manufacturing company has approved funding for a new identity and access management (IAM) initiative after several audit findings cited excessive privileged access and inconsistent user provisioning across regions. The board has stated that the program must reduce regulatory exposure, support the company's expansion into two new countries within 18 months, and avoid disrupting production systems. The CIO wants the CISO to finalize the project scope statement before vendor selection begins. Which scope statement is MOST appropriate?
- A
Implement an enterprise IAM program for corporate and plant environments that standardizes joiner-mover-leaver processes, strengthens privileged access controls for systems in scope, integrates with priority business applications in phases, and defines exclusions, success criteria, and constraints to support regulatory reduction and business expansion without unacceptable operational disruption.
- B
Deploy the market-leading IAM suite across all systems globally within 12 months, eliminate all access-related audit findings, and replace every legacy authentication mechanism regardless of business impact.
- C
Improve security by introducing stronger authentication and better provisioning wherever possible, with details to be determined by the selected vendor after the contract is signed.
- D
Acquire an IAM platform to satisfy audit requirements, with scope focused on installing the technology stack first and addressing business process changes in a later phase if budget remains.
Show answer and explanation
Correct answer: A
Explanation
The best answer is the one that produces a clear, bounded, business-aligned scope statement before execution and vendor selection. In CCISO practice, a scope statement for an information systems project should align with enterprise strategy, define included and excluded areas, identify key deliverables, acknowledge constraints and assumptions, and establish success criteria. Here, the board's objectives are explicit: reduce regulatory exposure, support international expansion, and avoid disruption to production. Therefore, the scope must connect security capabilities to those business outcomes rather than merely specifying a product rollout.
This approach is consistent with widely accepted project and governance practices. PMBOK-style project scope management emphasizes developing a detailed scope statement that includes product scope, deliverables, acceptance criteria, exclusions, constraints, and assumptions. COBIT governance principles similarly stress alignment of IT and security initiatives with enterprise goals and stakeholder needs. In security leadership, this means defining scope in business terms first, then using that scope to drive requirements, prioritization, procurement, and implementation planning.
A strong CCISO-level response recognizes that poorly defined scope leads to scope creep, weak vendor accountability, misaligned investment, and project outcomes that fail to support organizational objectives. The correct option best demonstrates strategic alignment, realistic boundaries, and executive-level governance discipline.
- A. Correct.
Correct. This option reflects a strong project scope statement because it ties the initiative directly to organizational objectives: reducing regulatory exposure, enabling expansion, and minimizing operational disruption. It also defines what is included (joiner-mover-leaver standardization, privileged access controls, phased integration), implies what is not universally included through 'systems in scope' and phased delivery, and acknowledges constraints and success criteria. A proper scope statement should describe boundaries, deliverables, assumptions, constraints, and intended business outcomes rather than just naming a technology.
- B. Incorrect.
Incorrect. Although ambitious goals can be part of strategic intent, this is not an appropriate scope statement. It overcommits by asserting deployment across all systems globally within a fixed aggressive timeline and by implying replacement of every legacy authentication mechanism regardless of business impact. It also uses outcome language such as 'eliminate all access-related audit findings' that may not be fully controllable by the project itself. This reflects a common mistake of confusing scope with an aspirational mandate and ignoring business constraints.
- C. Incorrect.
Incorrect. This option is too vague to guide governance, resource planning, or vendor evaluation. It lacks defined boundaries, deliverables, priorities, constraints, and measurable outcomes. Deferring core scope definition until after vendor selection is poor practice because the organization should establish business-aligned requirements and scope before procurement, otherwise the vendor may shape the project in ways that do not support enterprise objectives.
- D. Incorrect.
Incorrect. This option is overly technology-centric and not sufficiently aligned with organizational objectives. IAM success depends heavily on business processes, governance, role design, onboarding/offboarding workflows, and risk-based prioritization, not just tool installation. Limiting initial scope to technology deployment may satisfy a narrow procurement objective but does not adequately address the stated goals of regulatory risk reduction, support for expansion, and protection of production operations.