712-50 Question 219
Single answerA newly appointed CISO has been asked to launch a 12-month enterprise information security program that includes identity governance, vulnerability management, security awareness, and third-party risk oversight. The board has approved funding but expects a delivery roadmap within two weeks. Several business units are already requesting project start dates, yet the security team has inconsistent workload data and relies heavily on two senior architects who are also supporting regulatory remediation work. To produce a realistic schedule and staffing plan, which action should the CISO take FIRST?
- A
Build a work breakdown structure for the program, identify dependencies and required skill sets, estimate effort and duration for each activity, and then perform resource leveling before publishing milestones
- B
Commit to board-level target dates immediately and require each security manager to align staffing afterward so the program demonstrates urgency
- C
Assign all major workstreams to the two senior architects because they have the strongest security expertise and can accelerate planning assumptions
- D
Outsource the entire planning exercise to a consulting firm and defer internal activity sequencing until implementation begins
Show answer and explanation
Correct answer: A
Explanation
The best answer is to first create a structured activity-based program plan before committing to delivery dates. In a CCISO context, successful execution of an information systems security program requires translating strategic objectives into defined activities, sequencing those activities, estimating effort and duration, and developing a staffing plan based on required capabilities and actual capacity. In practice, this means building a work breakdown structure, identifying dependencies across workstreams, estimating duration using available historical data and expert judgment, and performing resource analysis or leveling to account for constrained personnel. This is consistent with established project and program management good practice reflected in PMI scheduling and resource planning guidance, as well as governance expectations found in frameworks such as COBIT and NIST program management concepts. A CISO who publishes dates before this analysis risks creating an unrealistic roadmap, especially when critical staff are already overloaded and multiple business units are competing for security support.
- A. Correct.
Correct. This is the most appropriate first step because it establishes the foundation for an executable program plan. A CISO should decompose the program into manageable activities, identify sequencing and dependencies, estimate effort/duration, map required competencies, and then validate the plan against actual resource constraints. Resource leveling is particularly important in this scenario because two key architects are overcommitted. This approach aligns with standard project and program management practices such as defining activities, sequencing them, estimating durations, developing the schedule, and planning resources before committing to delivery dates.
- B. Incorrect.
Incorrect. Committing to dates before defining activities, dependencies, and resource availability is a common governance mistake. It may create an appearance of decisiveness, but it increases the likelihood of missed milestones, staff burnout, and poor prioritization. In this scenario, the team already lacks reliable workload data, so forcing dates first would produce a schedule driven by optimism rather than evidence.
- C. Incorrect.
Incorrect. Concentrating major workstreams on the two senior architects ignores capacity constraints and creates a key-person dependency. Although these architects are highly skilled, they are already committed to regulatory remediation. This option reflects a common misconception that the best experts should own most tasks, rather than using role-based staffing, delegation, and realistic capacity planning to reduce bottlenecks.
- D. Incorrect.
Incorrect. External consultants can help with facilitation or specialized expertise, but outsourcing the planning exercise does not remove the CISO's responsibility to define internal activities, dependencies, and staffing constraints. Deferring internal sequencing until implementation begins would weaken governance and likely cause rework, since the organization still needs a realistic integrated schedule tied to internal resource availability and business priorities.