712-50 exam dumps

712-50 practice question 225 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 225

Single answerAcquire, develop and manage information security project team

A newly appointed CISO has been asked to launch a 12-month identity and access management (IAM) transformation program across a global enterprise. The initiative includes privileged access management, access recertification, and integration with HR systems. Internal audit has already warned that prior security projects failed because technically strong staff were assigned without clear role definitions, development plans, or coordination with business stakeholders. Budget for new headcount is limited, but the board expects measurable progress within two quarters. Which action should the CISO take FIRST to acquire, develop, and manage the information security project team most effectively?

  1. A

    Create a project team structure based on required competencies, define roles and responsibilities, identify skill gaps, and then source a mix of internal staff and targeted external expertise to fill critical gaps

  2. B

    Assign the most experienced security engineers to the project immediately and allow them to determine responsibilities as implementation decisions are made

  3. C

    Outsource the entire IAM program to a systems integrator so the organization does not need to invest in team development during the first year

  4. D

    Begin technical implementation with existing infrastructure staff and request formal training only after the first audit milestone reveals capability weaknesses

Show answer and explanation

Correct answer: A

Explanation

The best first step is to design the project team intentionally around business and technical requirements, then close gaps through staffing, training, and selective external support. In CCISO-level practice, acquiring, developing, and managing the information security project team is not just a staffing exercise; it is a governance and leadership responsibility. Large security programs fail when organizations treat them as purely technical efforts instead of cross-functional transformations requiring clear accountability, competency mapping, and stakeholder alignment. Best practices from project and security governance disciplines support defining roles, responsibilities, and required competencies up front, assessing current staff capabilities, and using a balanced sourcing strategy. This approach is consistent with principles found in PMI resource planning, NIST NICE workforce concepts for cybersecurity roles and skills, and general governance expectations for segregation of duties, accountability, and sustainable capability development.

  • A. Correct.

    Correct. For a major security transformation, the CISO should first establish the team model around the competencies required to deliver the program, such as IAM architecture, project management, business analysis, HR integration, access governance, and change management. Defining roles and responsibilities early reduces ambiguity and accountability gaps, while a skills assessment supports an informed sourcing strategy using internal talent where possible and external specialists where necessary. This aligns with sound program governance, workforce planning, and security leadership practices.

  • B. Incorrect.

    Incorrect. Although experienced engineers are valuable, assigning people before defining the operating model often recreates the exact failure pattern described in the scenario: unclear ownership, weak coordination, and role confusion. Technical seniority alone does not ensure the project has the right mix of business, governance, and delivery skills. This option reflects a common misconception that expertise can compensate for weak team design.

  • C. Incorrect.

    Incorrect. A systems integrator may help deliver specialized components, but outsourcing the entire program as the first response weakens internal ownership and does not address the need to build and manage a sustainable security capability. IAM transformation typically requires ongoing governance, stakeholder engagement, and operational integration that cannot be delegated completely without increasing long-term dependency and control risk.

  • D. Incorrect.

    Incorrect. Starting implementation before assessing and addressing capability needs is reactive and increases the likelihood of delays, rework, and audit findings. Waiting for an audit milestone to reveal predictable skill gaps is poor management practice. Effective CISOs proactively identify team development and resource needs at project initiation rather than after control failures or schedule slippage occur.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam