712-50 Question 29
Single answerCreate risk assessment schedule and checklistsA newly appointed CISO is standardizing the enterprise risk assessment program across a global organization with data centers, cloud workloads, and several recently acquired business units. Internal audit has reported that assessments are performed inconsistently: some business units are reviewed annually, while others are assessed only after major incidents. The board has asked for a defensible risk assessment schedule and supporting checklists that can be used consistently across the enterprise and justified during regulatory reviews. Which approach should the CISO take FIRST to build the most effective assessment schedule and checklists?
- A
Create a uniform annual assessment schedule for all business units and develop a single checklist covering all control domains to ensure consistency.
- B
Prioritize the schedule using asset criticality, regulatory obligations, threat exposure, and recent environmental changes, then tailor checklists by assessment scope while maintaining a common baseline.
- C
Schedule assessments only for business units that experienced control failures or security incidents in the previous year, and use incident-specific checklists to maximize efficiency.
- D
Base the schedule primarily on internal audit availability and create checklists from the last external audit report so the organization can prepare for likely auditor questions.
Show answer and explanation
Correct answer: B
Explanation
The best first step is to establish a risk-based schedule and checklist framework. In practice, a CISO should define assessment frequency and scope using criteria such as asset value, business criticality, legal and regulatory obligations, exposure to current threats, dependency on third parties, and organizational change events such as mergers, cloud migrations, or major architecture changes. Checklists should include a common baseline so assessments remain comparable across the enterprise, but they should also be tailored for specific contexts such as cloud platforms, operational technology, acquired entities, or privacy-regulated processes. This aligns with widely accepted practices in risk management and governance, including NIST SP 800-30 for risk assessments, NIST SP 800-37 for ongoing authorization and periodic assessment concepts, ISO 27001/27005 risk management principles, and audit/risk governance expectations that security activities be risk-driven and repeatable. A defensible schedule is not simply annual, incident-driven, or audit-driven; it is based on enterprise risk criteria and supported by structured, fit-for-purpose checklists.
- A. Incorrect.
This is incorrect because a uniform annual schedule may be easy to administer, but it does not reflect risk-based prioritization. In mature governance programs, risk assessments should be scheduled based on factors such as business criticality, regulatory requirements, material system changes, and threat landscape. A single checklist for every environment also ignores differences among data centers, cloud services, and acquired entities, which can lead to gaps or unnecessary review steps.
- B. Correct.
This is correct because it applies a risk-based methodology to scheduling and checklist design. High-value assets, regulated processes, internet-facing systems, newly integrated acquisitions, and environments with significant change should be assessed more frequently or earlier. Maintaining a common baseline checklist supports consistency, while tailoring checklists by scope ensures relevance for different environments and assessment types. This approach is defensible to boards, auditors, and regulators because it aligns assessment activity to business and risk drivers rather than convenience.
- C. Incorrect.
This is incorrect because it is too reactive. Prior incidents and control failures are important inputs, but they should not be the sole basis for scheduling assessments. Waiting for failures can leave high-risk but as-yet-uncompromised areas unassessed. Incident-specific checklists also narrow the focus too much and can miss broader governance, architecture, third-party, or compliance risks that should be part of a structured enterprise risk assessment process.
- D. Incorrect.
This is incorrect because audit availability and prior audit findings may influence logistics and remediation follow-up, but they should not drive the primary assessment schedule. Building checklists mainly from prior external audit questions can produce a compliance-centric checklist rather than a true risk assessment instrument. Risk assessments should evaluate business impact, likelihood, changing threats, and control effectiveness, not simply prepare for audits.