712-50 Question 240
Single answerResolve personnel and teamwork issues within time, cost, and quality constraintsA CISO is leading a 90-day program to implement centralized privileged access management after an audit finding. Midway through the project, conflict develops between the security engineering lead and the infrastructure operations manager. Engineering wants to enforce all privileged access controls immediately to meet audit quality requirements, while operations argues that doing so will increase outage risk during a peak business period. Team morale is declining, milestones are slipping, and the approved budget does not allow for adding staff or extending the program. What is the BEST action for the CISO to take FIRST to resolve the personnel and teamwork issue while still managing time, cost, and quality constraints?
- A
Escalate the disagreement to the CEO and request a decision on which team has authority over the rollout plan
- B
Direct the security engineering lead to proceed immediately with the full implementation because audit remediation quality takes priority over schedule concerns
- C
Facilitate a structured decision meeting with both leaders to re-baseline scope and sequencing based on business risk, define a phased rollout with agreed acceptance criteria, and assign clear accountability for milestones
- D
Replace both managers with individual contributors who are more willing to follow the original project plan
Show answer and explanation
Correct answer: C
Explanation
The best first action is to resolve the conflict through structured leadership and risk-based program management rather than through immediate escalation, unilateral direction, or disruptive staffing changes. In CCISO-level practice, resolving personnel and teamwork issues requires balancing security quality objectives with business continuity, schedule, and budget constraints. A phased implementation is often the most practical response when full immediate deployment creates operational risk and no additional budget or time is available. This reflects common best practices from project and service management disciplines: clarify objectives, align stakeholders, define decision criteria, assign accountability, and manage delivery through agreed milestones and acceptance criteria. From a governance perspective, the CISO should ensure that decisions are based on enterprise risk tolerance, business impact, and control priorities rather than on functional bias from either team. This approach also supports audit remediation because it demonstrates managed progress, documented decision-making, and executive oversight rather than unmanaged delay or conflict.
- A. Incorrect.
This is not the best first action. Escalation to the CEO may be appropriate only after the CISO has attempted to resolve the conflict through governance, risk-based prioritization, and management intervention. Immediate executive escalation can undermine leadership credibility, slow decision-making, and worsen team dynamics. In a constrained project, the CISO should first try to align stakeholders at the appropriate management level using agreed risk, business impact, and delivery criteria.
- B. Incorrect.
This is incorrect because it prioritizes one project dimension, control completeness, without balancing operational risk, schedule feasibility, and stakeholder buy-in. A chief information security officer is expected to manage security outcomes in a business context, not force technically correct but operationally destabilizing decisions. Proceeding unilaterally can deepen conflict, damage trust, and create service disruption, which could ultimately reduce overall program success.
- C. Correct.
This is the best answer. The core problem is not only technical disagreement but also unresolved conflict affecting delivery. A structured meeting led by the CISO allows the leaders to focus on shared objectives, audit remediation, operational stability, and deadline adherence. Re-baselining scope and sequencing supports time and cost constraints when additional resources are unavailable. A phased rollout with explicit acceptance criteria preserves quality by defining what must be delivered first, what can be deferred based on risk, and who owns each milestone. This approach reflects executive leadership, stakeholder management, and practical program governance.
- D. Incorrect.
This is incorrect because replacing managers mid-project is highly disruptive, costly in transition time, and unlikely to be the best first response to a conflict rooted in competing priorities. It also risks harming morale further and may introduce additional delivery risk. Effective CISOs address performance and collaboration issues through leadership, role clarity, conflict resolution, and governance before making major personnel changes.