712-50 Question 223
Single answerA newly appointed CCISO is leading the design and implementation of an enterprise information security program after a series of audit findings revealed fragmented tooling, unclear ownership, and insufficient staffing for monitoring and incident response. The organization is preparing its annual planning cycle, and the CFO has requested a defensible resource proposal tied to business outcomes. The CCISO must secure funding for additional analysts, a centralized logging platform, and external architecture support while also ensuring the program can be sustained after implementation. Which action should the CCISO take FIRST to most effectively identify, negotiate, acquire, and manage the resources needed for a successful program rollout?
- A
Develop a risk-based business case that maps required people, technology, and architectural capabilities to prioritized business services, control gaps, implementation dependencies, and measurable outcomes
- B
Request immediate approval for the full security budget by emphasizing recent audit findings and the potential reputational damage of another incident
- C
Purchase the centralized logging platform first so the security team can demonstrate quick wins and justify future headcount requests with operational data
- D
Outsource most security operations to a managed service provider to avoid the delays associated with hiring and internal capability development
Show answer and explanation
Correct answer: A
Explanation
The best first action is to create a risk-based, business-aligned resource strategy that clearly identifies what capabilities are needed, why they are needed, and how they support enterprise objectives. In CCISO practice, resource acquisition is not simply a budgeting exercise; it requires translating risk, compliance obligations, architecture requirements, and operational gaps into a justified portfolio of people, infrastructure, and services. This approach supports negotiation with the CFO and business leaders because it frames the request in terms they value: risk reduction, resilience, regulatory readiness, and support for business services.
Widely accepted practices from frameworks such as NIST CSF, NIST SP 800-53, COBIT, and ISO/IEC 27001 emphasize aligning security investments with organizational context, risk treatment priorities, governance, and operational sustainability. For example, ISO 27001 highlights ensuring necessary resources are available for establishing, implementing, maintaining, and continually improving the information security management system. COBIT similarly stresses aligning resource optimization with enterprise goals. Therefore, before purchasing tools or selecting sourcing models, the CCISO should identify current-state and target-state capabilities, dependencies, ownership, and measurable outcomes, then use that analysis to negotiate phased and sustainable resource commitments.
- A. Correct.
Correct. A CCISO should begin by establishing a risk-based, business-aligned resource plan. This means identifying which business services and information assets are most critical, assessing current control and capability gaps, and translating those gaps into specific resource needs across people, process, and technology. By linking requested resources to measurable outcomes such as reduced detection time, improved audit compliance, or support for strategic initiatives, the CCISO creates a defensible basis for negotiation with finance and business leadership. This also supports phased acquisition and longer-term resource management rather than isolated spending.
- B. Incorrect.
Incorrect. Audit findings and reputational risk are relevant inputs, but asking for full budget approval first without a structured capability and dependency analysis is weak governance and often ineffective with executive stakeholders. Finance leaders typically expect justification tied to business priorities, risk reduction, sequencing, and expected value. This option reflects a common mistake of relying on urgency alone instead of building a defensible investment case.
- C. Incorrect.
Incorrect. Buying technology before validating operating model, staffing, architecture, data sources, and integration requirements often leads to underutilized tools and failed implementations. A centralized logging platform may be necessary, but acquiring it first does not address whether the organization has the analysts, use cases, retention model, onboarding plan, and governance needed to realize value. This is a common misconception that tooling should lead program design.
- D. Incorrect.
Incorrect. Outsourcing can be an appropriate sourcing strategy for some functions, but shifting most operations to a provider before defining capability requirements, risk appetite, accountability, and retained internal responsibilities is premature. The CCISO still must determine which capabilities should be internal versus external, how service levels will be governed, and how the outsourced model aligns with business and regulatory needs. This option confuses a possible acquisition method with the first strategic step.