712-50 exam dumps

712-50 practice question 227 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 227

Single answerAssign clear information security personnel job functions and provide continuous training to ensure effective performance and accountability

A newly appointed CISO at a global manufacturing company finds that several security incidents were mishandled because analysts, system owners, and IT operations managers had overlapping responsibilities and inconsistent skill levels across regions. During a post-incident review, the board asks for a corrective action that will improve accountability and ensure staff can perform their assigned security duties effectively over time. Which action should the CISO prioritize FIRST?

  1. A

    Develop and approve role-based security job descriptions with explicit responsibilities, decision rights, escalation paths, and required competencies, then align a recurring training and assessment program to those roles

  2. B

    Increase the security budget to acquire additional monitoring tools so personnel can rely more on automation than on formal role definition and training

  3. C

    Require all IT staff to attend the same annual security awareness course to create a uniform baseline and reduce regional differences

  4. D

    Outsource incident response activities to a managed security service provider so internal accountability issues become less significant

Show answer and explanation

Correct answer: A

Explanation

The scenario centers on two common leadership failures in security programs: unclear job functions and lack of continuous capability development. The most effective first step is to establish role clarity through documented responsibilities, authority, and escalation paths, then connect those roles to a continuous training and competency validation program. This creates accountability, improves performance consistency, and supports defensible governance. Best practices from frameworks such as ISO/IEC 27001 and ISO/IEC 27002 emphasize defining and allocating information security responsibilities, while NIST guidance and common governance models support role-based training, competency management, and periodic review of responsibilities. From a CCISO perspective, this is a governance and workforce management issue first, not primarily a tooling, awareness-only, or outsourcing issue.

  • A. Correct.

    This is the best answer because it addresses both root causes identified in the scenario: unclear ownership and inconsistent capability. Role-based job descriptions clarify accountability by defining who is responsible for which security functions, what authority they have, and when they must escalate. Mapping required competencies to each role and implementing recurring training and assessments ensures personnel remain capable as threats, technologies, and business processes evolve. This aligns with governance and workforce management best practices such as clearly defined roles and responsibilities, segregation of duties, and continuous professional development.

  • B. Incorrect.

    This is incorrect because tools can improve detection and response efficiency, but they do not resolve ambiguity in responsibilities or gaps in staff capability. Without clearly assigned job functions and training, even advanced tools may be misused, ignored, or produce uncoordinated responses. This option reflects the common misconception that technology can compensate for weak governance and unclear accountability.

  • C. Incorrect.

    This is incorrect because general annual security awareness training is useful for the broader workforce, but it does not adequately prepare specialized personnel for distinct operational and decision-making responsibilities. Analysts, system owners, and operations managers require role-specific training tied to their duties. A uniform awareness course may create a baseline culture of security, but it will not solve the scenario's problems of overlapping responsibilities and inconsistent professional competence.

  • D. Incorrect.

    This is incorrect because outsourcing may provide additional expertise, but it does not remove the organization's responsibility to define internal ownership, oversight, escalation, and accountability. Internal stakeholders still need clear roles for vendor management, incident coordination, business decision-making, and risk acceptance. This option may seem attractive when internal maturity is low, but it treats a governance problem as a sourcing problem.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam