712-50 Question 228
Select 2A newly appointed CISO inherits a security organization in which the SOC, infrastructure operations, technical support, incident management, and security engineering teams all report through different business units. During recent malware and privilege misuse incidents, investigations were delayed because teams used different ticketing queues, escalation paths were unclear, and system administrators sometimes made changes before incident responders could preserve evidence. The CISO has been asked to improve coordination without changing the reporting structure immediately. Which TWO actions would BEST establish effective communication and team activities across these groups while preserving operational accountability?
- A
Create a cross-functional incident governance model with a RACI matrix, shared escalation criteria, and defined handoff procedures between SOC, IT operations, technical support, incident management, and security engineering.
- B
Require all security-related communications to flow only through the CISO's office so that messaging remains controlled and consistent across teams.
- C
Implement shared operational playbooks and communication channels for common incident types, including evidence preservation steps, change control expectations, and decision points for each team.
- D
Move technical support and infrastructure operations under the security department immediately so the CISO has direct authority over every responder.
- E
Allow each team to retain its own incident procedures, but mandate a weekly status meeting to discuss any issues that arose during the previous week.
Show answer and explanation
Correct answers: A, C
Explanation
The best answer is to establish formal cross-functional governance and operationalize it through shared playbooks and communication mechanisms. In this scenario, the CISO's challenge is to direct information security personnel and coordinate activities among security and non-security teams that have different reporting structures. Effective leadership at the CCISO level requires defining accountability, communication paths, escalation triggers, and decision authorities so that security operations, IT operations, technical support, and incident management can act cohesively during time-sensitive events.
A RACI matrix and handoff procedures are particularly useful when multiple teams participate in containment, forensic preservation, restoration, and engineering remediation. Shared playbooks then translate governance into practical execution. This approach aligns with established best practices found in incident response and governance guidance such as NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes clearly defined roles, reporting chains, and coordinated procedures, and with ISO/IEC 27035 principles for structured incident management. It also reflects broader governance concepts from COBIT and common security operating model practices, where communication, accountability, and repeatable processes are more effective than ad hoc escalation or executive micromanagement.
The incorrect choices reflect common leadership mistakes: over-centralizing communication through executives, assuming organizational restructuring alone will solve process failures, or relying on meetings without standard operating procedures. A mature CISO function enables cross-team execution through governance, playbooks, and communication channels that work under operational pressure.
- A. Correct.
This is correct because a cross-functional governance model clarifies who is responsible, accountable, consulted, and informed at each stage of an incident or security activity. In a fragmented organization, the immediate problem is not necessarily hierarchy but ambiguity. A RACI matrix, common escalation thresholds, and formal handoff procedures reduce delays, minimize duplicated effort, and improve coordination between operational and security teams while preserving existing reporting lines.
- B. Incorrect.
This is incorrect because centralizing all communications through the CISO creates a bottleneck and slows tactical response. Executive oversight is important, but day-to-day operational coordination should be enabled through pre-defined channels and delegated authority. In mature security programs, the CISO establishes governance and escalation frameworks rather than personally mediating every communication.
- C. Correct.
This is correct because shared playbooks operationalize the governance model. They give teams a common understanding of who does what during malware, insider misuse, privilege abuse, or other common scenarios. Including evidence preservation, change control, containment approval points, and communication paths helps prevent administrators or support staff from taking well-intentioned actions that compromise investigations or recovery sequencing.
- D. Incorrect.
This is incorrect because reorganizing reporting lines may eventually be considered, but it is not the best immediate solution to the stated problem. The scenario specifically asks for improvement without changing the reporting structure immediately. Also, structural consolidation alone does not guarantee clear processes, handoffs, or communication discipline.
- E. Incorrect.
This is incorrect because a weekly meeting may improve visibility but does not solve real-time coordination failures during active incidents. Retaining inconsistent procedures without standardization leaves the root cause unaddressed. Meetings are useful as a supporting mechanism for lessons learned and continuous improvement, but they are insufficient as the primary control.