712-50 Question 229
Single answerA newly appointed CISO at a global manufacturing company finds that security engineering, incident management, and technical support operate in silos. During a recent ransomware incident, the security operations team identified malicious lateral movement, but technical support delayed isolating affected endpoints because they were waiting for infrastructure approval. At the same time, security engineering pushed a firewall change that disrupted forensic collection, and business unit IT managers complained they were not informed about response priorities. The CEO asks the CISO to establish a communication and coordination model that improves cross-functional execution without creating excessive bureaucracy. Which action should the CISO take FIRST?
- A
Implement a formal RACI matrix and incident communication/escalation workflow that defines decision rights, handoff points, and approved communication channels across security operations, technical support, infrastructure, and business IT
- B
Acquire a SOAR platform to automate containment approvals so that endpoint isolation and firewall changes can occur without human intervention
- C
Require all security-related teams to report directly to the CISO so that conflicts between technical support, incident management, and engineering are eliminated
- D
Instruct security engineering to stop making any production changes during incidents unless the CISO personally approves each action
Show answer and explanation
Correct answer: A
Explanation
This question tests the CCISO candidate's ability to lead cross-functional security execution by establishing governance, communications, and operating mechanisms between information security personnel and related teams such as technical support, incident management, infrastructure, and security engineering. In the scenario, the core problem is fragmented coordination: teams are acting independently, dependencies are unmanaged, business stakeholders are not informed, and authority for response actions is unclear. A senior security leader should first define an operating model that clarifies roles, responsibilities, escalation thresholds, communications paths, and approval boundaries.
A RACI matrix is a practical governance tool because it distinguishes who is Responsible, Accountable, Consulted, and Informed for critical actions such as containment, evidence preservation, production changes, and stakeholder notification. Combined with an incident communication plan, it reduces delays, prevents conflicting actions, and aligns technical and business teams during high-pressure events. This approach is consistent with established best practices in incident response and security governance, including guidance from NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide), which emphasizes predefined roles, communications, and coordination; NIST Cybersecurity Framework functions such as Respond and Recover; and ISO/IEC 27035 principles for incident management planning and coordination. From a CCISO perspective, the CISO's responsibility is not merely to choose tools or impose hierarchy, but to build an effective management structure that enables coordinated, repeatable execution across multiple operational teams.
- A. Correct.
Correct. The primary failure in the scenario is not a lack of tools, but unclear roles, decision authority, coordination points, and communication paths among security operations, technical support, engineering, and business IT. A RACI matrix combined with an incident communication and escalation workflow directly addresses these governance and operational alignment gaps. It clarifies who is responsible for actions such as endpoint isolation, who must be consulted before firewall changes, who approves exceptions, and how business stakeholders are informed. This is the most appropriate first step for a CISO seeking to direct information security personnel and establish effective team activities across related functions.
- B. Incorrect.
Incorrect. SOAR can improve speed and orchestration, but automation will not resolve confusion over ownership, authority, or stakeholder communications if the underlying process is broken. Automating containment approvals before establishing governance can actually amplify errors, such as isolating critical systems without business coordination or changing controls that interfere with investigations. Tools should support a well-defined operating model, not substitute for one.
- C. Incorrect.
Incorrect. Centralizing reporting lines may appear to reduce friction, but it is neither necessary nor the best first action. In many organizations, technical support, infrastructure, and business IT have legitimate separate reporting structures. Effective cross-functional coordination depends more on clearly defined authority, communication protocols, service expectations, and escalation procedures than on org-chart changes. Reorganization can be disruptive and may not solve the immediate operational failures described.
- D. Incorrect.
Incorrect. Requiring personal approval from the CISO for all production changes during incidents creates a bottleneck and weakens resilience. Executive oversight is important, but incident response requires timely action by designated operational leaders within preapproved decision thresholds. This option reflects an over-centralized command approach rather than a scalable communication and coordination model. It may also delay containment and recovery.