712-50 Question 26
Single answerCreate a risk assessment methodology and frameworkA newly appointed CISO is standardizing risk assessments across a global enterprise that includes manufacturing plants, cloud-hosted customer platforms, and a regulated financial services subsidiary. Different business units currently use inconsistent scoring methods, making it difficult to compare risks or prioritize treatment decisions at the executive level. The board has asked for a risk assessment methodology that supports consistent decision-making, aligns cyber risk with business impact, and can be used repeatedly across diverse environments. Which action should the CISO take FIRST when creating the enterprise risk assessment methodology and framework?
- A
Define a common risk taxonomy, impact criteria, likelihood model, and risk rating approach tied to business objectives and risk appetite
- B
Purchase an automated GRC platform so all business units can enter risks into a single dashboard with standardized reporting
- C
Require each business unit to retain its current scoring model and convert results into high, medium, and low ratings for board reporting
- D
Begin with a detailed control assessment against one security framework and use control gaps alone to determine enterprise risk priorities
Show answer and explanation
Correct answer: A
Explanation
The best first step in creating a risk assessment methodology and framework is to define a consistent enterprise-wide approach for how risk will be described, measured, and evaluated. This typically includes a common risk taxonomy, asset and process scoping, threat/vulnerability considerations, impact criteria, likelihood criteria, residual versus inherent risk definitions, and escalation thresholds aligned to risk appetite and tolerance. Only after these foundational elements are established should the organization implement tooling, reporting, and workflow automation.
This approach aligns with widely accepted risk management practices reflected in sources such as NIST SP 800-30 (Guide for Conducting Risk Assessments), NIST SP 800-39 (Managing Information Security Risk), ISO 31000 (risk management principles and guidelines), and ISO/IEC 27005 (information security risk management). These references emphasize that risk assessment must be repeatable, comparable, and tied to organizational context and decision-making. For a CCISO-level leader, the priority is building a methodology that enables governance and business-aligned prioritization across the enterprise, not simply collecting more risk data or focusing narrowly on control deficiencies.
- A. Correct.
Correct. Before tools, dashboards, or reporting can be effective, the organization needs a consistent methodology for identifying, analyzing, and evaluating risk. A common taxonomy, defined impact and likelihood criteria, and a repeatable scoring approach establish the foundation for comparability across business units. Tying these elements to business objectives and risk appetite ensures the methodology supports executive decision-making rather than producing isolated technical findings.
- B. Incorrect.
Incorrect. A GRC platform can support execution and reporting, but it does not solve the underlying methodological problem by itself. Automating inconsistent or poorly defined assessment criteria will simply scale inconsistency. The methodology must be defined first, then supported by tooling.
- C. Incorrect.
Incorrect. Converting different scoring systems into broad labels such as high, medium, and low may appear to create consistency, but it masks differences in assumptions, impact definitions, and likelihood calculations. This can lead to misleading aggregation and poor prioritization. A true enterprise framework requires standardized criteria, not superficial normalization.
- D. Incorrect.
Incorrect. Control assessments are useful inputs, but risk assessment should not be reduced to control gap analysis alone. Enterprise risk methodology must consider assets, threats, vulnerabilities, likelihood, business impact, legal and regulatory consequences, and organizational risk appetite. Starting only with a control framework may bias the program toward compliance or maturity scoring instead of actual business risk.