712-50 Question 234
Single answerIdentify stakeholders, manage stakeholders' expectations, and communicate effectively to report progress and performanceA newly appointed CISO is leading a 12-month identity and access management (IAM) modernization program after several audit findings showed excessive privileged access and inconsistent joiner-mover-leaver processes. Six weeks into the program, the board asks for a concise status update, the CFO wants clearer justification for continued spending, the IT operations director complains that security reporting is too technical, and business unit leaders are concerned that tighter controls will delay employee onboarding. The CISO needs to improve stakeholder management and communication without changing the program's strategic objectives. Which action is the MOST effective?
- A
Create a stakeholder communication plan that maps each stakeholder group to its interests, influence, required level of detail, reporting cadence, and success measures, then tailor reporting dashboards and messages accordingly
- B
Send the same detailed monthly security report to all stakeholders so everyone receives identical information and there is no risk of inconsistent messaging
- C
Escalate stakeholder concerns to the CEO and request that all program communications be routed through executive leadership to ensure authority and compliance
- D
Delay further communications until the IAM team can show measurable risk reduction so stakeholders receive only confirmed positive results
Show answer and explanation
Correct answer: A
Explanation
Effective CISOs do not merely report security activity; they manage stakeholder expectations by identifying who the stakeholders are, understanding what each group needs to make decisions, and communicating program performance in language relevant to their interests. In this scenario, the board, CFO, IT operations, and business unit leaders each represent distinct stakeholder groups with different concerns: governance and risk oversight, financial accountability, operational execution, and business impact. The best practice is to create a stakeholder communication plan or matrix that defines stakeholder roles, concerns, influence, reporting objectives, cadence, channels, and metrics. This approach supports governance principles reflected in frameworks such as COBIT, which emphasizes stakeholder needs and enterprise goals alignment, and NIST CSF governance-oriented practices, which stress communicating cybersecurity risk in a business context. Tailored reporting does not mean altering facts; it means presenting consistent facts in forms that are meaningful to each audience. This helps the CISO maintain credibility, secure support, reduce friction, and keep the program aligned with strategic objectives.
- A. Correct.
Correct. This is the most effective response because it directly addresses stakeholder identification, expectation management, and communication effectiveness. Different stakeholders need different information: the board typically needs strategic risk, trend, and decision-oriented summaries; the CFO needs business value, cost, and return/risk reduction rationale; IT operations needs actionable operational metrics in business-relevant language; and business leaders need impact, timeline, and mitigation of operational friction. A structured communication plan aligns reporting with stakeholder interests and influence, which is a core executive responsibility for a CISO.
- B. Incorrect.
Incorrect. Consistency of facts is important, but identical reporting is not the same as effective communication. A single technical report for all audiences usually fails because it does not account for differing responsibilities, decision rights, and levels of detail. This is a common misconception: treating equal distribution as good stakeholder management. In practice, communications should be consistent in substance but tailored in format, depth, and emphasis.
- C. Incorrect.
Incorrect. Executive sponsorship can help with major conflicts, but routing all communications through the CEO is excessive and weakens the CISO's leadership role. It also does not solve the underlying issue that stakeholders have different expectations and information needs. Over-escalation can damage trust and slow decision-making.
- D. Incorrect.
Incorrect. Withholding communication until there are only positive, measurable results is poor governance and expectation management. Stakeholders need timely, transparent progress reporting, including risks, dependencies, constraints, and anticipated business impacts. Delaying updates can create mistrust, increase resistance, and undermine support for the program.