712-50 Question 238
Single answerSecurity Program Operations (6 questions)A newly appointed CISO inherits a global security operations program that has grown rapidly through acquisitions. The board has approved additional funding, but the COO has warned that business units will resist any initiative that slows product releases or increases operating costs without measurable benefit. Current issues include inconsistent incident handling across regions, duplicated tools, and weekly dashboards that show large volumes of alerts but little insight into business risk. The CISO must improve day-to-day security program operations within the next two quarters while building executive confidence. Which action should the CISO take FIRST to create the strongest operational foundation?
- A
Standardize core security operations processes and metrics across business units, including incident classification, escalation criteria, service-level targets, and risk-based reporting tied to critical business services
- B
Purchase an enterprise SOAR platform to automate alert triage across all acquired environments and reduce analyst workload before redesigning existing processes
- C
Increase the number of weekly operational dashboards sent to executives so leadership has more visibility into alert volumes, phishing attempts, and blocked attacks by region
- D
Outsource regional security monitoring to separate managed security service providers so each acquired business can maintain local autonomy while reducing staffing pressure
Show answer and explanation
Correct answer: A
Explanation
In CCISO-level security program operations, the CISO's role is not merely to add tools or increase monitoring output, but to establish an operating model that is measurable, scalable, and aligned to business priorities. The scenario highlights classic post-acquisition operational issues: inconsistent processes, overlapping technologies, and metrics that report activity instead of risk. The most effective first move is to normalize operations through standardized processes, service expectations, and risk-based metrics.
This approach aligns with widely accepted practices in security operations and governance. NIST Cybersecurity Framework emphasizes consistent operational processes across Identify, Protect, Detect, Respond, and Recover functions, while NIST SP 800-61 highlights the importance of defined incident handling procedures, classification, and escalation. ISO/IEC 27001 and ISO/IEC 27002 also support establishing standardized operating procedures, roles, responsibilities, and performance evaluation mechanisms. From an executive leadership perspective, security metrics should be outcome-oriented and mapped to business services, not just technical event counts.
Once process consistency and metrics are in place, the CISO can make stronger decisions on automation, sourcing strategy, and tooling rationalization. That sequencing is what makes Option 1 the strongest answer.
- A. Correct.
This is the best first step because effective security program operations depend on consistent, repeatable processes, clearly defined responsibilities, and meaningful metrics. In the scenario, the core problems are operational inconsistency, duplicated activity, and reporting that does not translate security activity into business impact. Standardizing incident taxonomy, escalation thresholds, SLAs, and metrics creates governance and comparability across regions, enabling better oversight, rationalization of tools, and more credible reporting to executives. Tying reporting to critical business services shifts the program from activity-based measures to risk-informed operational performance, which is what the board and COO need to support future investments.
- B. Incorrect.
This is plausible because automation can improve efficiency, but it is not the strongest first action. Automating poorly defined or inconsistent processes usually amplifies existing inefficiencies and can create fragmented workflows across acquired environments. Before deploying SOAR or similar automation, the CISO should establish standard workflows, escalation paths, and data definitions. Otherwise, the organization risks expensive tool implementation without operational alignment or measurable business improvement.
- C. Incorrect.
This is incorrect because increasing dashboard frequency or volume does not address the underlying issue that the current dashboards emphasize alert counts rather than business risk. Executives generally need decision-useful metrics, such as incident response timeliness for critical services, reduction in control gaps, and operational resilience indicators. More activity reporting may create noise and reduce confidence rather than improve operational effectiveness.
- D. Incorrect.
This option may seem attractive because outsourcing can relieve staffing shortages, but it does not solve the immediate governance and consistency problem. Using separate providers for separate regions can actually increase fragmentation, complicate escalation, and make enterprise-wide metrics less reliable. Outsourcing may be part of a future operating model, but the CISO should first define standardized processes, accountability, and reporting requirements that any internal or external provider must follow.