712-50 Question 274
Single answerA newly appointed CISO is integrating physical security across a global enterprise that includes headquarters, regional offices, and a colocated data center operated by a third party. A recent internal review found inconsistent badge access practices, no formal testing of visitor controls, and no enterprise metrics to show whether physical safeguards are effective. The board has asked for a comprehensive physical security plan that is coordinated with information security, includes an audit schedule, and uses measurable performance indicators. Which action should the CISO take FIRST to build the most effective program?
- A
Establish a risk-based physical security governance framework that defines minimum control standards for all sites, maps responsibilities across facilities/HR/security/IT, sets a recurring audit schedule based on site criticality, and tracks metrics such as unauthorized access attempts, badge review completion, visitor log exceptions, and remediation closure times
- B
Deploy biometric readers and CCTV with centralized monitoring at all locations immediately, then evaluate whether policies and metrics are needed after the technology rollout stabilizes
- C
Require each regional facility manager to create site-specific physical security procedures independently because local teams understand their environments better than corporate leadership
- D
Outsource all physical security responsibilities to the colocation provider and building landlords, relying on their existing certifications and annual attestations as evidence of sufficient control
Show answer and explanation
Correct answer: A
Explanation
The best answer is the risk-based governance framework because the scenario calls for a comprehensive, coordinated, and holistic physical security plan with an audit schedule and performance metrics. At the executive level, physical security should be managed as part of enterprise security governance, not as isolated site implementations or purely technical deployments. A strong program typically includes: enterprise physical security policy and standards; clear roles among security, facilities, HR, IT, legal, and third parties; risk-tiering of sites and assets; recurring audits and control testing based on criticality; exception handling; and metrics that measure both compliance and effectiveness.
Relevant best practices are consistent with established frameworks and guidance. NIST SP 800-53 includes physical and environmental protection controls (PE family) that emphasize access authorization, visitor control, monitoring, and review. ISO/IEC 27001 and ISO/IEC 27002 address physical security through controls related to secure areas, entry controls, equipment protection, and monitoring, all of which should be governed and measured. Performance metrics should be meaningful to management, such as frequency of badge access reviews, number of tailgating or unauthorized access incidents, visitor processing exceptions, mean time to remediate audit findings, and percentage of critical sites assessed on schedule. A CISO should first establish the governance and measurement foundation so that technologies, local procedures, and third-party arrangements can be implemented and monitored consistently across the enterprise.
- A. Correct.
Correct. This is the strongest first step because it creates a comprehensive, coordinated, and risk-based program rather than a collection of disconnected controls. A governance framework aligns physical security with enterprise risk management and information security, establishes minimum baselines across varied sites, and clarifies accountability among business functions that share physical security responsibilities. A risk-based audit schedule is appropriate because critical facilities such as data centers and headquarters generally require more frequent and deeper reviews than low-risk offices. The included metrics are practical and measurable, helping leadership assess both control effectiveness and operational performance. This approach supports continuous improvement and executive oversight.
- B. Incorrect.
Incorrect. Technology can be an important component of physical security, but leading with broad deployment before governance, standards, roles, audit criteria, and success measures are defined is a common error. It may result in inconsistent implementation, unnecessary cost, and metrics that do not tie back to risk reduction. A holistic CCISO-level approach starts with governance, risk prioritization, and performance measurement rather than assuming that more technology alone will solve process and oversight gaps.
- C. Incorrect.
Incorrect. Local input is valuable, but allowing each region to define controls independently undermines consistency, enterprise oversight, and comparability of results. This would likely perpetuate the exact problem identified in the review: inconsistent practices. In a mature program, corporate leadership sets minimum standards and governance requirements, while sites may tailor implementation to local legal, cultural, and operational conditions within approved boundaries.
- D. Incorrect.
Incorrect. Third-party physical security controls can be part of the overall model, especially for colocation and leased facilities, but accountability cannot be fully transferred. The organization still needs to define requirements, validate provider controls, integrate them into its own risk assessments and audit schedule, and monitor performance. Certifications and attestations are useful inputs, but they are not a substitute for internal governance, oversight, and coordinated assurance activities.