712-50 exam dumps

712-50 practice question 221 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 221

Single answerDevelop, manage and monitor the information systems program budget, estimate and control costs of individual projects

A newly appointed CISO is preparing the annual information security program budget during a period of cost pressure. The board has approved a fixed funding envelope, but several security initiatives are competing for resources, including IAM modernization, SOC tooling improvements, third-party risk management automation, and a data loss prevention rollout. Midyear, the CFO asks the CISO to justify why two projects are overrunning their estimates while another high-profile project is requesting accelerated funding. Which action should the CISO take FIRST to improve budget control and support defensible funding decisions across the program?

  1. A

    Re-baseline all security projects to align with the original annual budget and defer variance reporting until year-end to avoid unnecessary concern

  2. B

    Prioritize projects based primarily on business risk reduction, establish cost baselines and measurable deliverables for each project, and monitor variances through regular review with project owners

  3. C

    Shift funds from lower-cost operational activities such as awareness training and policy maintenance into the most visible strategic project requested by senior leadership

  4. D

    Request an immediate budget increase for the security program because emerging threats make the original budget assumptions obsolete

Show answer and explanation

Correct answer: B

Explanation

In CCISO practice, budgeting is not just about obtaining funds; it is about governing security investments as a portfolio aligned to enterprise risk, business priorities, and measurable outcomes. The best first action is to establish or reinforce cost baselines, expected deliverables, and regular variance monitoring for each project, then use those data points to reprioritize spending according to risk reduction and strategic value. This reflects common governance and financial management practices found in frameworks such as ISACA's governance guidance, PMI project cost management principles, and NIST-aligned risk management approaches. A CISO should be able to explain where money is being spent, what risk is being reduced, why variances exist, and what corrective action is needed. Choices that delay reporting, fund initiatives based on visibility alone, or immediately seek more budget without internal analysis reflect weak fiscal stewardship.

  • A. Incorrect.

    This is incorrect because simply re-baselining projects back to the original annual budget does not address the root causes of overruns or improve governance. Deferring variance reporting until year-end weakens management oversight and reduces the CISO's ability to take corrective action in time. Effective budget management requires timely monitoring, variance analysis, and adjustment based on actual project performance rather than delaying transparency.

  • B. Correct.

    This is correct because the CISO must link spending to business risk reduction and treat the security budget as a portfolio of initiatives with defined cost baselines, milestones, and expected outcomes. Establishing measurable deliverables enables earned-value-style performance tracking or similar governance mechanisms, while regular variance reviews help identify scope creep, underestimation, dependency issues, or execution problems early. This approach supports both cost control for individual projects and defensible prioritization at the program level.

  • C. Incorrect.

    This is incorrect because reallocating funds based mainly on visibility or executive pressure rather than risk, value, and control effectiveness is poor governance. Operational activities such as awareness, policy maintenance, and other foundational controls often provide ongoing risk reduction and compliance support. Diverting funds without structured analysis can increase residual risk and create imbalances in the overall security program.

  • D. Incorrect.

    This is incorrect because requesting more money may eventually be necessary, but it is not the first step when the issue is weak budget control and justification. The CISO should first demonstrate disciplined financial management by analyzing project variances, validating assumptions, reprioritizing based on risk and business objectives, and presenting evidence-based options. A request for additional budget is more credible after these management controls have been applied.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam