712-50 Question 224
Single answerAcquire, develop and manage information security project teamA newly appointed CISO has been asked to deliver a 12-month enterprise identity and access management (IAM) transformation program across multiple business units. The organization has strong infrastructure engineers but limited experience in IAM architecture, role engineering, and business process redesign. Budget approval is likely only if the CISO can show a credible staffing approach that reduces delivery risk and builds long-term internal capability. Which approach is the BEST way for the CISO to acquire, develop, and manage the information security project team?
- A
Staff the project entirely with the existing infrastructure team and expect them to learn IAM during implementation to minimize upfront cost.
- B
Outsource the entire program to a systems integrator and keep internal staff out of the project to avoid delays caused by a learning curve.
- C
Create a blended team with targeted external IAM specialists for critical design roles, assign internal high-potential staff to work alongside them, and define knowledge transfer and capability development as contractual deliverables.
- D
Delay the program until the organization can hire a full permanent IAM team so that no external dependency is introduced.
Show answer and explanation
Correct answer: C
Explanation
In CCISO-level leadership, acquiring, developing, and managing an information security project team is not just a resourcing exercise; it is a risk management and capability-building decision. The strongest approach is to identify which competencies are mission-critical and scarce, bring in external experts selectively for those roles, and pair them with internal staff to create durable organizational knowledge. This reflects widely accepted program and talent management practices found in sources such as PMI guidance on resource planning and team development, NIST NICE Workforce Framework concepts for aligning roles to required competencies, and general governance principles emphasizing sustainable internal capability over pure outsourcing. A senior security leader should optimize for successful delivery, reduced dependency, and succession of skills into operations, not merely short-term cost or convenience.
- A. Incorrect.
This is not the best approach because it underestimates the specialized skills required for IAM transformation, particularly architecture, governance, role modeling, and business integration. While developing existing staff is important, relying entirely on them in a high-visibility program creates unnecessary execution risk, schedule slippage, and weak design decisions. A CISO should align staffing decisions to risk, critical competencies, and business impact rather than focusing only on immediate cost containment.
- B. Incorrect.
This option may appear attractive because it can bring in expertise quickly, but it is not the best strategic choice. Excluding internal staff prevents the organization from developing sustainable capability, reduces ownership of the target operating model, and increases long-term vendor dependency. For a CISO, effective team management includes building internal maturity and ensuring security capabilities remain embedded in the organization after the project ends.
- C. Correct.
This is the best answer because it balances immediate delivery needs with long-term organizational capability. A blended staffing model allows the CISO to place scarce specialist talent in the highest-risk roles while using the project as a development platform for internal staff. Requiring structured knowledge transfer, mentoring, documentation, and shadowing in contracts helps ensure skills remain in-house. This approach is consistent with executive-level security leadership practices: acquire missing capabilities strategically, develop internal talent deliberately, and manage resources to reduce both delivery and operational risk.
- D. Incorrect.
This is not the best answer because delaying a strategic security program until all ideal permanent hires are made is often impractical and can increase business risk. In competitive labor markets, specialized roles may take months to fill, and the organization may continue operating with known IAM weaknesses. A CISO should manage constraints pragmatically by combining hiring, external expertise, and internal development rather than waiting for perfect staffing conditions.