712-50 exam dumps

712-50 practice question 30 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 30

Single answerCreate risk assessment schedule and checklists

A newly appointed CISO is formalizing the enterprise risk assessment program for a global manufacturer that has corporate IT, multiple plants running OT systems, a growing cloud environment, and several critical third-party logistics providers. Historically, assessments were performed inconsistently and only after major incidents. The board has asked for a predictable risk assessment schedule and standardized checklists that improve coverage without overwhelming business units. Which approach is the MOST effective?

  1. A

    Establish an annual enterprise-wide risk assessment for all business units using one standard checklist, and allow exceptions only after a security incident occurs.

  2. B

    Create a risk-based schedule that sets assessment frequency according to asset criticality, threat exposure, regulatory obligations, and material business change, and use tailored checklists for IT, OT, cloud, and third-party domains.

  3. C

    Schedule risk assessments only for systems handling regulated data, because those environments have the clearest checklist requirements and audit drivers.

  4. D

    Require each business unit leader to define their own schedule and checklist so the process reflects local operational realities and reduces central governance overhead.

Show answer and explanation

Correct answer: B

Explanation

The best answer is the risk-based scheduling model with domain-specific checklists. In CCISO practice, the CISO is expected to ensure risk assessments are repeatable, defensible, and aligned to business impact. Best practice is to define a baseline cadence, then adjust frequency using criteria such as asset criticality, data sensitivity, internet exposure, regulatory and contractual obligations, major system changes, mergers, new suppliers, and prior assessment results. Checklists should be standardized enough to support consistency and reporting, but tailored enough to address the distinct control and risk considerations of IT, OT, cloud, and third-party environments. This approach aligns with widely accepted guidance from ISO 27005 on information security risk management, NIST SP 800-30 on conducting risk assessments, and broader governance principles in ISO 31000 and NIST CSF, all of which support risk-based prioritization rather than purely calendar-driven or compliance-only assessment planning.

  • A. Incorrect.

    This is not the most effective approach because a single annual cycle and one generic checklist are too rigid for a diverse environment. Critical OT systems, cloud changes, and high-risk suppliers may require more frequent assessments than low-risk business processes. Waiting for incidents to justify exceptions is reactive and inconsistent with a mature risk management program.

  • B. Correct.

    This is correct because it aligns assessment frequency and checklist content with risk drivers. A mature CISO-led program should schedule assessments based on factors such as business criticality, inherent risk, regulatory requirements, significant architecture or vendor changes, and threat landscape changes. Tailored checklists improve relevance and completeness across different domains while preserving standard governance. This supports efficient resource use and better risk visibility for leadership.

  • C. Incorrect.

    This is incorrect because it narrows the scope of risk assessment too much. Regulatory scope is only one factor in enterprise risk management. Critical manufacturing systems, cloud administration platforms, and strategic third parties can create major business risk even if they do not primarily process regulated data. Choosing this option reflects the common misconception that compliance scope equals enterprise risk scope.

  • D. Incorrect.

    This is incorrect because decentralized ownership without central governance usually leads to inconsistent frequency, uneven quality, and gaps in reporting. Business input is important, but the CISO should define minimum standards, trigger events, and core checklist requirements to ensure comparability and enterprise-wide oversight. Leaving scheduling entirely to business units often recreates the same inconsistency the organization is trying to fix.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam