712-50 Question 24
Single answerCreate a risk management program policy and charterA newly appointed CISO at a global manufacturing company has been asked by the board's risk committee to formalize the organization's enterprise cyber risk management program. Different business units currently assess risk differently, some accept risks without executive visibility, and internal audit has noted that no document clearly defines authority, scope, reporting, or decision rights for cyber risk management. The CISO must draft a risk management program policy and charter that will be reviewed by executive leadership and the board. Which action would BEST establish an effective foundation for the program?
- A
Create a policy and charter that define the program's purpose, scope, governance structure, roles and responsibilities, risk appetite alignment, reporting cadence, and authority for risk escalation and acceptance
- B
Issue a technical standard requiring all business units to use the same vulnerability scanning tool and classify the standard as the enterprise risk management charter
- C
Publish a risk register template first and allow each business unit to decide its own acceptance thresholds until the program matures
- D
Delegate ownership of the risk management charter to internal audit so the document remains independent from security operations
Show answer and explanation
Correct answer: A
Explanation
For a CCISO-level leader, the first priority in creating a risk management program policy and charter is to establish governance, accountability, and authority before focusing on tooling or templates. A charter typically defines why the program exists, who sponsors it, what its scope is, how decisions are made, who can accept risk, how exceptions are escalated, and how results are reported to executive leadership and the board. The policy then operationalizes expectations for consistent risk identification, analysis, treatment, monitoring, and communication across the enterprise. This aligns with widely accepted governance and risk management practices reflected in frameworks such as ISO 31000, ISO/IEC 27005, NIST Risk Management guidance, and the Three Lines Model, all of which emphasize defined roles, risk criteria, governance structure, and management accountability. In this scenario, the most effective foundation is the option that explicitly creates board-relevant governance and decision-rights clarity.
- A. Correct.
Correct. A risk management program policy and charter should establish the mandate and operating model for the program. At the executive level, this includes defining purpose, scope, governance, roles, accountability, authority, decision rights, escalation paths, reporting expectations, and how risk decisions align to enterprise risk appetite and business objectives. This approach addresses the scenario's core problems: inconsistent assessments, unclear authority, and ungoverned risk acceptance.
- B. Incorrect.
Incorrect. A technical standard may support implementation consistency, but it is not a substitute for a policy and charter. Standardizing a tool does not define governance, authority, reporting, or risk acceptance decision rights. This option reflects a common mistake of treating technical controls as equivalent to program governance.
- C. Incorrect.
Incorrect. A risk register template is useful operationally, but starting with templates while allowing each unit to set its own acceptance thresholds perpetuates inconsistency and weak governance. Risk acceptance thresholds should be aligned to approved enterprise risk appetite and documented authority, not left to decentralized interpretation without oversight.
- D. Incorrect.
Incorrect. Internal audit should remain independent and provide assurance over the effectiveness of governance and controls, not own the risk management charter. Program ownership should typically reside with executive management, with the CISO or designated risk function responsible for drafting and operating the program under board-approved governance.