712-50 Question 226
Single answerAssign clear information security personnel job functions and provide continuous training to ensure effective performance and accountabilityA newly appointed CISO at a global manufacturing company finds that security incidents are frequently mishandled because responsibilities overlap between the SOC, infrastructure team, application owners, and regional IT managers. Recent audit results also showed that several staff members with security responsibilities had not completed role-specific training for more than a year. The CISO wants to improve accountability and operational effectiveness without slowing business operations. Which action should the CISO take FIRST?
- A
Develop and approve a role-based security responsibility matrix with explicit ownership, decision rights, escalation paths, and mandatory training requirements tied to each role
- B
Require all personnel in IT and security to attend the same annual security awareness course before changing any job descriptions
- C
Outsource incident handling to a managed security service provider so internal staff no longer need detailed role definitions or specialized training
- D
Implement stricter disciplinary actions for teams involved in mishandled incidents to reinforce accountability before revising governance documents
Show answer and explanation
Correct answer: A
Explanation
The best first action is to formally define and document security job functions and align continuous training to those responsibilities. In mature security governance, personnel accountability depends on clear role definition, documented authority, separation of duties where needed, and competency management. Practical mechanisms include RACI charts, role descriptions, decision-rights matrices, onboarding requirements, recurring training plans, and periodic competency reviews. This approach is consistent with widely recognized practices in security governance and workforce management, including NIST SP 800-53 controls such as AT-2 (Literacy and Training), AT-3 (Role-Based Training), and PM/PS family concepts related to defined roles and responsibilities, as well as ISO/IEC 27001 and 27002 guidance on organizing information security and ensuring personnel are competent on the basis of education, training, or experience. For a CCISO, the key leadership judgment is to fix structural accountability and capability gaps before applying punitive measures or assuming that outsourcing or generic awareness training will resolve operational confusion.
- A. Correct.
Correct. The core issue is unclear accountability combined with stale or missing role-specific training. A role-based responsibility matrix, often implemented through a RACI or similar governance model, clarifies who is responsible, accountable, consulted, and informed for key security processes such as incident response, vulnerability management, and exception handling. Including decision rights and escalation paths reduces confusion during time-sensitive events. Tying mandatory training requirements to each role ensures personnel maintain the competencies needed to execute assigned duties effectively. This is the most appropriate first step because it addresses root causes in governance, performance, and accountability.
- B. Incorrect.
Incorrect. A general annual awareness course is useful for broad employee education, but it does not solve the identified problem of overlapping security responsibilities and missing role-specific competence. SOC analysts, system administrators, incident managers, and application owners need targeted training aligned to their operational duties. Using only a common awareness course is a common misconception because it treats all training needs as equivalent, when effective security programs distinguish between awareness, role-based training, and specialized technical development.
- C. Incorrect.
Incorrect. An MSSP may provide operational support, but outsourcing does not remove the organization's responsibility to define internal ownership, oversight, escalation authority, and accountability. The enterprise still needs clear internal job functions for vendor management, incident decision-making, legal/regulatory coordination, and business risk acceptance. This option is attractive to leaders seeking quick relief, but it avoids the governance weakness rather than correcting it.
- D. Incorrect.
Incorrect. Accountability mechanisms are important, but applying stricter discipline before clarifying expected responsibilities and ensuring appropriate training is poor management practice and may create a blame culture. Staff cannot be held fairly accountable for outcomes when job functions are ambiguous and competence expectations are not formally established. Effective governance typically defines roles, communicates expectations, provides training, and then measures performance against those standards.