712-50 Question 218
Single answerA newly appointed CISO has been asked to launch a 12-month information security program across three business units after the board approved funding. The program includes policy updates, identity and access management improvements, third-party risk assessments, and security awareness training. The board expects a realistic delivery roadmap within two weeks. Initial review shows that key security engineers are already committed to major infrastructure projects, compliance deadlines vary by business unit, and several activities depend on procurement and legal review. What should the CISO do FIRST to build the most reliable schedule and staffing plan for executing the program?
- A
Create a high-level annual timeline based on the board's target date, then assign available staff evenly across all workstreams to avoid delays
- B
Define the program work breakdown structure, identify dependencies and resource constraints, estimate effort and duration with input from accountable managers, and then develop the schedule and staffing plan
- C
Prioritize the most visible control implementations first, outsource the remaining activities, and finalize the staffing plan after vendors are selected
- D
Use the prior year's security program schedule as a template, adjust dates for the new budget cycle, and request additional headcount only if milestones are missed
Show answer and explanation
Correct answer: B
Explanation
The best answer is to begin with structured program planning: define activities through a work breakdown structure or equivalent decomposition, identify dependencies and constraints, estimate effort and duration using knowledgeable stakeholders, and then build a schedule and staffing plan based on actual resource capacity. This is consistent with established project management practices such as those in PMI PMBOK guidance on activity definition, sequencing, duration estimating, schedule development, and resource planning. In an information security context, this also reflects sound governance: security initiatives often depend on legal, procurement, business-unit availability, and specialized technical skills, so plans must account for both internal and external dependencies. A CISO is expected to provide realistic execution plans that balance board expectations with operational feasibility, not simply produce optimistic dates or reuse prior templates without validation.
- A. Incorrect.
This is incorrect because it starts with a target-date-driven timeline and equal staff allocation rather than a structured definition of activities, dependencies, and actual resource capacity. In security program management, spreading staff evenly across workstreams often ignores critical path, specialized skills, sequencing, and external dependencies such as procurement or legal review. This approach can produce an attractive roadmap but not a reliable executable plan.
- B. Correct.
This is correct because the CISO must first break the program into definable activities, identify sequencing and dependencies, assess resource availability and constraints, and estimate effort and duration with the people responsible for execution. That creates the basis for a defensible schedule and staffing plan. This reflects standard project and program management practice: define scope and tasks, determine dependencies, estimate durations and resource needs, and then build the schedule. It also aligns with security leadership expectations to create a realistic, risk-informed delivery plan rather than a purely aspirational one.
- C. Incorrect.
This is incorrect because it prematurely selects implementation priorities and a sourcing model before the CISO has established the full set of activities, constraints, and interdependencies. Outsourcing may be appropriate for some tasks, but deciding that before activity decomposition and estimation can create cost, governance, and timeline problems. It also ignores the requirement to develop a reliable overall schedule and staffing plan for the whole program.
- D. Incorrect.
This is incorrect because prior schedules may offer reference data, but using them as the primary planning method is risky when the current program involves different business units, compliance deadlines, and resource constraints. Waiting to request headcount until milestones are missed is reactive and weak from a governance perspective. Effective CISOs identify staffing gaps during planning, not after slippage occurs.