712-50 exam dumps

712-50 practice question 3 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 3

Single answerGovernance (6 questions)

A newly appointed CISO joins a global manufacturing company after a ransomware incident disrupted operations for three days. During the post-incident review, the board states that it receives highly technical security reports but still cannot determine whether cyber risk is being managed within the organization's risk appetite. The CEO asks the CISO to redesign security governance so that board oversight improves without pulling the board into day-to-day operations. Which action should the CISO take FIRST to address this governance gap?

  1. A

    Implement additional endpoint detection and response tools and provide the board with monthly alert volumes to show increased visibility

  2. B

    Establish board-approved cyber risk appetite statements and a security metrics framework that maps key risk indicators and key performance indicators to business objectives

  3. C

    Require the board to review and approve all security incident response playbooks so directors can directly oversee operational preparedness

  4. D

    Outsource security operations to a managed security service provider and use the provider's service-level reports as the primary governance dashboard

Show answer and explanation

Correct answer: B

Explanation

The key governance issue is not insufficient operational data, but the absence of a board-level mechanism to express expectations and evaluate management performance against them. In effective information security governance, the board sets direction through strategy and risk appetite, while management implements controls and reports performance in business terms. The most appropriate first step is therefore to define or formalize cyber risk appetite at the board level and create a reporting structure that links security metrics to enterprise objectives and risk thresholds. This allows directors to perform their oversight role without managing operations. This approach aligns with recognized best practices in ISO/IEC 27014, which distinguishes governance from management; COBIT, which emphasizes alignment of enterprise goals, risk, and performance measures; and NIST cyber risk management concepts, which stress communicating risk in terms decision-makers can act on.

  • A. Incorrect.

    This is incorrect because adding tools and reporting alert volumes does not solve the core governance problem. The board has already indicated that technical reporting is not enabling effective oversight. Alert counts are operational metrics, not business-aligned governance measures. A common misconception is that more tooling or more data automatically improves governance, when the real issue is whether reporting supports risk-based decision-making.

  • B. Correct.

    This is correct because governance starts with clear direction and oversight from leadership. Board-approved cyber risk appetite statements define the level and types of cyber risk the organization is willing to accept, and a metrics framework aligned to business objectives translates security performance into meaningful oversight information. This enables the board to assess whether management is operating within approved boundaries without becoming involved in operational execution. This is consistent with governance principles found in frameworks such as COBIT, ISO/IEC 27014, and NIST guidance emphasizing risk-based communication to senior leadership.

  • C. Incorrect.

    This is incorrect because it pulls the board into management activities rather than strengthening governance. Incident response playbooks are typically management-level operational documents. The board should approve strategy, risk appetite, and oversight mechanisms, not detailed operational procedures. Candidates may choose this option because it appears to increase accountability after an incident, but it violates the governance-management separation expected at the executive level.

  • D. Incorrect.

    This is incorrect because outsourcing operations does not address the lack of internal governance structure. Service-level reports from a provider may be useful for vendor oversight, but they are not a substitute for enterprise cyber governance, board-defined risk appetite, or business-aligned risk reporting. This option reflects the misconception that transferring operational responsibility also transfers accountability; in reality, accountability for governance remains with organizational leadership.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam