712-50 Question 23
Single answerCreate a risk management program policy and charterA newly hired CISO at a global manufacturing company has been asked by the board risk committee to formalize an enterprise risk management program for information security. Different business units currently assess risk inconsistently, several executives dispute who owns treatment decisions, and internal audit has reported that there is no formally approved mandate for the program. The CISO must draft both a risk management policy and a program charter before launching the initiative. Which action should the CISO take FIRST to make the program sustainable and enforceable across the enterprise?
- A
Publish detailed risk assessment procedures for analysts so each business unit can begin scoring risks immediately
- B
Obtain executive sponsorship and board-level approval for a charter that defines purpose, scope, authority, governance, and accountability for risk decisions
- C
Deploy a governance, risk, and compliance (GRC) tool to standardize workflow and reporting across all business units
- D
Set a single enterprise risk appetite threshold within the security team and require all business units to align to it
Show answer and explanation
Correct answer: B
Explanation
The best first step is to secure executive sponsorship and formal approval of a risk management program charter that clearly establishes the program's mandate. In practice, the charter should define why the program exists, what parts of the enterprise it covers, who has authority to make and approve risk decisions, how exceptions and escalations are handled, and how the program interfaces with business units, audit, legal, compliance, and executive leadership. The associated policy then sets mandatory expectations, such as use of a common methodology, reporting requirements, review cadence, and risk ownership responsibilities.
This sequencing is consistent with recognized best practices. ISO 31000 emphasizes leadership, integration, and governance as prerequisites for effective risk management. NIST SP 800-39 highlights the need for organization-wide risk governance, including roles, responsibilities, and risk executive oversight. From a CCISO perspective, the CISO must ensure the risk program is not merely a security team activity but an enterprise governance function with explicit accountability and support from senior management. Once the charter and policy are approved, the organization can then define procedures, select tools, and operationalize assessments in a consistent and sustainable way.
- A. Incorrect.
This is premature. Procedures are important, but they should flow from approved governance documents. Without a formally authorized charter and policy, business units may not accept the process, roles may remain unclear, and the procedures may lack enforceability. A common mistake is to start with operational detail before establishing executive mandate and governance.
- B. Correct.
This is correct. A charter provides the formal mandate for the program, including purpose, scope, authority, governance structure, stakeholder roles, escalation paths, and decision rights. Executive sponsorship and board or senior leadership approval are critical because risk acceptance, prioritization, and treatment funding typically require business ownership and enterprise authority. Establishing this governance foundation first aligns with good practices in risk management frameworks such as NIST SP 800-39, which emphasizes organization-wide risk governance, and ISO 31000, which stresses leadership and commitment.
- C. Incorrect.
A GRC platform can help operationalize the program, but technology does not solve governance gaps. If scope, authority, ownership, and policy expectations are not approved first, the tool may simply automate inconsistent or disputed practices. This option reflects a common misconception that tooling should precede governance design.
- D. Incorrect.
This is inappropriate because risk appetite is an enterprise leadership decision, not something the security team should define unilaterally. The CISO can facilitate and recommend thresholds, but business executives and the board must approve organizational risk appetite and tolerances. Requiring alignment before obtaining executive agreement would undermine the legitimacy of the program.