712-50 Question 237
Single answerEnsure that necessary changes and improvements to the information systems processes are implemented as requiredA newly appointed CISO inherits an annual security review process that consistently identifies the same control deficiencies in identity and access management, patch governance, and privileged account monitoring. Internal audit reports show that remediation plans are documented, but business units frequently delay implementation because process changes are seen as disruptive to operations. The board has asked the CISO to ensure that necessary improvements are actually implemented, not just identified. Which action should the CISO take FIRST to most effectively drive sustainable implementation of these process improvements across the organization?
- A
Require all business unit leaders to immediately implement the audit recommendations and report completion within 30 days
- B
Establish a formal remediation governance process with defined owners, risk-based prioritization, target dates, escalation thresholds, and executive reporting
- C
Commission an external consulting firm to independently validate the audit findings before any remediation work begins
- D
Increase the frequency of technical vulnerability scans so that business units receive more evidence of unresolved weaknesses
Show answer and explanation
Correct answer: B
Explanation
At the CCISO level, the key responsibility is not merely identifying control weaknesses, but ensuring corrective changes are governed, prioritized, funded, tracked, and enforced across the enterprise. In this scenario, the repeated appearance of the same audit findings indicates a failure in remediation governance rather than a failure in detection. A mature information security program should include a formal corrective action or issue management process with clear ownership, timelines, risk ranking, dependency management, exception handling, and escalation to senior leadership when implementation stalls. This approach aligns with widely accepted governance and control practices reflected in frameworks such as NIST Cybersecurity Framework governance and improvement activities, NIST SP 800-53 concepts around Plan of Action and Milestones (POA&M), ISO/IEC 27001 requirements for continual improvement and corrective action, and COBIT's emphasis on governance, accountability, and performance monitoring. The CISO's first priority should be to establish the mechanism that makes process improvement executable and enforceable across business units.
- A. Incorrect.
This is not the best first action. While urgency is important, simply mandating implementation within a fixed period does not address the root cause: lack of governance, accountability, prioritization, and escalation. Some findings may require architectural changes, budget approval, or business process redesign, making a blanket 30-day deadline unrealistic. This option reflects a common misconception that executive directives alone are sufficient to ensure process change.
- B. Correct.
This is the best answer. The scenario indicates that issues are repeatedly identified but not implemented due to operational resistance. A formal remediation governance process creates the management structure needed to translate findings into action. Defined ownership ensures accountability, risk-based prioritization helps focus effort on the most significant exposures, target dates create measurable commitments, escalation thresholds address delays, and executive reporting provides oversight and pressure for follow-through. This is the most effective first step for institutionalizing change and ensuring improvements are implemented as required.
- C. Incorrect.
This is not the best first action because the scenario already states that internal audit has repeatedly identified the same deficiencies. Revalidating known findings delays corrective action and may be perceived as avoidance. External validation can be useful in some cases, especially for disputed findings or regulatory scrutiny, but here the primary issue is implementation failure, not uncertainty about the findings.
- D. Incorrect.
This is incorrect because increasing scan frequency may generate more data, but it does not resolve the governance and accountability gap preventing process improvements from being implemented. The problem is not lack of awareness of weaknesses; it is the organization's inability or unwillingness to execute remediation. This option represents a common operational bias toward collecting more technical evidence instead of fixing process execution.