712-50 Question 22
Single answerRisk Management (6 questions)A global manufacturing company is acquiring a smaller firm to gain access to its proprietary industrial control software. During due diligence, the CISO learns that the target company has no formal vulnerability management program, uses several unsupported operating systems in its development environment, and stores source code in a cloud repository administered by a single engineer. The CEO wants the acquisition completed within 45 days because of competitive pressure. The board asks the CISO for a recommendation that balances business objectives with security risk. Which action should the CISO recommend FIRST?
- A
Delay the acquisition until all identified security weaknesses are remediated and independently validated
- B
Accept the risk because the acquired company will eventually be brought under the parent company's security program after closing
- C
Perform a formal cyber risk assessment of the target, quantify the business impact, and present risk treatment options with associated costs and timelines to executive leadership
- D
Require the target company to sign an attestation that its environment is secure enough for integration and proceed with the acquisition
Show answer and explanation
Correct answer: C
Explanation
In a CCISO context, risk management is primarily about enabling informed executive decision-making, not unilaterally blocking or approving business activity. In an acquisition scenario, the CISO should first ensure cyber risks are assessed in a structured manner, translated into business impact, and compared against the organization's risk appetite and strategic priorities. This includes identifying material weaknesses, estimating integration and remediation costs, assessing potential impact to intellectual property, operations, and regulatory obligations, and presenting treatment options to leadership. This approach is consistent with established risk management practices in frameworks such as NIST SP 800-39 (Managing Information Security Risk), NIST SP 800-30 (Guide for Conducting Risk Assessments), and ISO 31000/ISO 27005, which emphasize risk identification, analysis, evaluation, and treatment in support of organizational objectives. The key leadership principle is that the CISO should provide decision-quality risk information so executives and the board can make a business-informed choice.
- A. Incorrect.
This is not the best first action. Although delaying the acquisition may ultimately be appropriate for certain high risks, a CCISO should first ensure risks are formally identified, analyzed, and communicated in business terms. Immediate delay without structured risk assessment and treatment analysis bypasses governance and may not align with the organization's risk appetite or strategic objectives.
- B. Incorrect.
This is incorrect because it assumes future remediation is an adequate substitute for current risk evaluation. In mergers and acquisitions, inherited cyber risk can materially affect valuation, integration cost, regulatory exposure, and operational continuity. Simply accepting the risk without formal assessment and executive risk decision-making is poor governance.
- C. Correct.
This is correct. The CISO's first responsibility is to enable an informed business decision by conducting a formal cyber risk assessment, determining likelihood and impact, identifying material issues, and presenting risk treatment options such as remediation before close, compensating controls, escrow/holdback terms, phased integration, or risk acceptance. This approach aligns security with enterprise risk management and allows leadership to decide within the organization's risk appetite.
- D. Incorrect.
This is incorrect because a contractual attestation alone does not meaningfully reduce the underlying risk. It may offer limited legal recourse, but it is not a substitute for due diligence, technical assessment, or a risk treatment plan. Relying on attestation reflects a common misconception that compliance statements equal effective risk management.