712-50 Question 220
Single answerDevelop, manage and monitor the information systems program budget, estimate and control costs of individual projectsA newly appointed CISO is reviewing a security program portfolio halfway through the fiscal year. One major identity and access management (IAM) project is 30% over budget because of integration effort that was underestimated during planning, while several lower-priority awareness and tooling initiatives have not yet started. The board has made it clear that the IAM project is critical to meeting regulatory expectations this year, but it also expects tighter budget discipline across the security program. What is the MOST appropriate action for the CISO to take?
- A
Rebaseline the IAM project using updated cost estimates, present the business justification and trade-offs to governance stakeholders, and defer or reduce lower-priority initiatives to keep the overall security program within approved budget limits
- B
Continue funding all projects as originally approved so that no business unit perceives a change in security commitment, then request a supplemental budget at year-end if the overrun remains
- C
Immediately stop the IAM project until a full independent audit is completed, because any project exceeding its estimate indicates unacceptable financial control failure
- D
Shift the IAM overrun into next year's budget forecast so the current year's program appears on target, while keeping the original project baseline for reporting consistency
Show answer and explanation
Correct answer: A
Explanation
In the CCISO domain of governance and security risk management, senior security leaders are expected to develop, manage, and monitor the information security program budget at both project and portfolio levels. The key issue in this scenario is not merely that one project is over budget, but how the CISO should respond in a way that preserves business value, supports compliance obligations, and maintains financial discipline. The best practice is to re-estimate and rebaseline when material assumptions change, perform variance analysis, and bring options with clear trade-offs to the appropriate steering committee or governance body. This aligns with common portfolio and project management practices such as earned value and forecast-based control, and with governance principles found in frameworks like COBIT and PMI guidance: transparency, prioritization, and alignment of spending to business objectives. A mature CISO does not hide overruns, passively wait for supplemental funding, or automatically terminate critical work without analysis. Instead, the CISO manages costs proactively by adjusting scope, timing, and prioritization across the program while preserving the highest-value and highest-risk-reduction initiatives.
- A. Correct.
Correct. This is the strongest budget-management response because it combines cost control, realistic re-estimation, and portfolio-level decision-making. A CISO is expected to manage the information security program budget, not just individual projects in isolation. Rebaselining based on current facts improves forecast accuracy; presenting business justification and trade-offs supports governance and accountability; and deferring lower-priority work is an appropriate way to protect a critical, compliance-driven initiative while staying within overall funding constraints.
- B. Incorrect.
Incorrect. This reflects weak budget governance and poor cost control. Continuing all projects without adjustment ignores the need to actively monitor and manage the program budget. Waiting until year-end to request additional funds reduces transparency and limits leadership's ability to make informed prioritization decisions earlier, when corrective action is still possible.
- C. Incorrect.
Incorrect. Although independent review may be appropriate in some cases, immediately stopping a critical IAM project solely because it is over budget is not the most appropriate response. Overruns can result from legitimate estimation gaps, scope complexity, or dependency issues. The CISO should first assess the revised business case, root cause, and alternatives before disrupting a project tied to regulatory expectations.
- D. Incorrect.
Incorrect. Moving current overruns into next year's budget to make the present year look compliant is poor financial practice and undermines governance integrity. Keeping the original baseline unchanged for reporting consistency also conceals actual performance. Effective cost management requires transparent reporting, updated forecasts, and timely escalation of variances.