712-50 Question 25
Single answerCreate a risk assessment methodology and frameworkA newly appointed CISO is tasked with establishing an enterprise-wide risk assessment methodology for a global manufacturing company that has grown through acquisitions. Each business unit currently assesses risk differently: one uses qualitative heat maps, another uses financial impact estimates, and a third only tracks compliance findings. The board has asked for a consistent method that supports strategic decision-making, prioritizes treatment funding, and can be repeated across regions with different regulatory requirements. Which approach should the CISO take FIRST to create the most effective risk assessment methodology and framework?
- A
Standardize on a single risk register template and require all business units to submit their top 10 risks each quarter
- B
Define enterprise risk criteria, scoring scales, risk appetite/tolerance thresholds, and assessment procedures aligned to business objectives before selecting tools or reports
- C
Adopt the business unit's existing methodology that produces the highest estimated losses so the board can prioritize the most severe exposures
- D
Begin with a vulnerability scanning program across all regions and use the scan results as the baseline for the new risk methodology
Show answer and explanation
Correct answer: B
Explanation
To create an effective enterprise risk assessment methodology, the CISO should first define the foundational framework: scope, governance, asset and process context, risk criteria, likelihood and impact definitions, scoring model, risk appetite and tolerance thresholds, assessment frequency, documentation standards, and escalation/reporting requirements. This ensures assessments are repeatable, comparable, and aligned with strategic objectives. Established guidance such as NIST SP 800-30 emphasizes defining assumptions, constraints, risk models, and assessment approaches before execution. ISO 31000 and ISO/IEC 27005 likewise stress establishing context and risk criteria before analysis and evaluation. In a CCISO context, the key leadership principle is that risk methodology must support executive decision-making and resource allocation, not merely technical findings or compliance tracking. Once the criteria and process are set, the organization can then choose tools, templates, and data sources that fit the framework.
- A. Incorrect.
This is incomplete and therefore incorrect as the first step. A common template can improve consistency in reporting, but it does not by itself create a defensible risk assessment methodology. Without defined risk criteria, impact and likelihood scales, assessment scope, ownership, and escalation thresholds, different business units may still interpret and score risks inconsistently. A risk register is an output of the methodology, not the methodology itself.
- B. Correct.
This is correct. The first priority in building an enterprise risk assessment methodology is to establish the framework elements that drive consistency and decision usefulness: common risk criteria, defined likelihood and impact scales, risk appetite and tolerance thresholds, governance, assessment procedures, and alignment to business objectives. This allows different regions and business units to evaluate risk in a repeatable way while still accommodating regulatory and operational differences. Once these elements are defined, supporting artifacts such as templates, tools, and reporting can be standardized effectively.
- C. Incorrect.
This is incorrect because it selects a methodology based on dramatic output rather than suitability, consistency, or alignment to enterprise governance. Higher loss estimates do not mean the methodology is better. This option reflects a common misconception that the most conservative or alarming model is automatically the most useful for executives. In practice, the methodology should be chosen and tailored based on business context, data quality, decision needs, and comparability across the enterprise.
- D. Incorrect.
This is incorrect because vulnerability data represents only one input into risk assessment and does not by itself constitute a risk methodology. Risk assessment must consider assets, business processes, threats, vulnerabilities, existing controls, likelihood, impact, and organizational risk criteria. Starting with scanning may help identify technical issues, but it would bias the framework toward IT vulnerabilities and away from broader enterprise risks such as supply chain disruption, legal exposure, fraud, safety, or third-party concentration risk.