712-50 exam dumps

712-50 practice question 235 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 235

Single answerIdentify stakeholders, manage stakeholders' expectations, and communicate effectively to report progress and performance

A newly appointed CISO is leading a 12-month identity and access management (IAM) transformation after several audit findings and one privileged access incident. The board wants a quarterly view of risk reduction and program status, while business unit leaders are concerned that stronger controls will delay employee onboarding and disrupt customer-facing operations. After the first steering committee meeting, several executives complain that the security team is reporting too much technical detail and not enough business impact. What should the CISO do FIRST to improve stakeholder management and communication for the program?

  1. A

    Create a stakeholder communication plan that maps each stakeholder group to its interests, decision needs, preferred level of detail, and reporting cadence, then tailor program metrics and messages accordingly

  2. B

    Standardize all reporting on detailed technical IAM metrics so every stakeholder receives the same complete view of implementation progress

  3. C

    Escalate the complaints to the CEO and request a mandate requiring business leaders to accept the security team's reporting format

  4. D

    Delay further stakeholder reporting until the IAM architecture is finalized so that the program status is more precise and less likely to be misunderstood

Show answer and explanation

Correct answer: A

Explanation

This question tests a CISO's ability to identify stakeholders, manage expectations, and communicate progress in a business-relevant manner. In executive security leadership, communication should be audience-specific. Boards and senior executives generally need risk, financial, compliance, and strategic outcome reporting, while operational leaders need implementation impacts, timing, resource requirements, and business disruption considerations. A formal stakeholder communication plan is a widely accepted best practice in governance and program management because it clarifies stakeholder interests, influence, information needs, decision rights, and reporting cadence. This aligns with principles reflected across ISACA governance guidance, PMBOK stakeholder and communications management practices, and NIST CSF governance-oriented reporting concepts, all of which emphasize translating security activity into business impact and risk reduction. The CISO should first establish a structured communication approach, then use metrics that show both progress and performance, such as reduction in privileged account risk, percentage of critical applications onboarded, onboarding cycle-time impact, exception trends, and unresolved program risks.

  • A. Correct.

    Correct. The core issue is not lack of activity but misalignment between stakeholder needs and the way information is being communicated. A stakeholder communication plan is the most appropriate first step because it identifies who the stakeholders are, what outcomes they care about, what decisions they must make, and what level of detail they need. For example, the board typically needs concise reporting on risk reduction, regulatory exposure, budget, milestones, and major obstacles, while business unit leaders need operational impact, implementation timing, dependencies, and service-level implications. Tailoring communication in this way helps manage expectations, builds trust, and improves decision-making.

  • B. Incorrect.

    Incorrect. Using one detailed technical report for all audiences is a common mistake. It may satisfy the security team, but it does not address the different needs of executives, board members, and business leaders. Boards usually need strategic, risk-based summaries rather than implementation detail, and business leaders need practical impact on operations and timelines. Standardizing the format without tailoring the content would likely worsen the communication problem.

  • C. Incorrect.

    Incorrect. Escalating to the CEO at this stage avoids the CISO's responsibility to engage stakeholders and adapt communication. While executive sponsorship is important, using authority to force acceptance of an ineffective reporting model damages relationships and does not solve the underlying issue of mismatched expectations. Effective CISOs build alignment through stakeholder analysis, governance, and communication rather than relying first on top-down mandates.

  • D. Incorrect.

    Incorrect. Delaying reporting would reduce transparency and could erode confidence in the program, especially given prior audit findings and a privileged access incident. Stakeholders need timely updates even when some details are still evolving. The better approach is to provide appropriately framed updates with clear assumptions, status indicators, risks, and next steps rather than waiting for perfect precision.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam