712-50 exam dumps

712-50 practice question 38 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 38

Single answerCompliance (6 questions)

A global SaaS company is preparing to enter several highly regulated markets. The board asks the CISO to reduce audit fatigue caused by overlapping customer, regulatory, and contractual compliance requests while still demonstrating due diligence to regulators. The company currently performs separate assessments for ISO/IEC 27001, SOC 2, PCI DSS, and regional privacy obligations, with different control owners responding to each request independently. Which action should the CISO take FIRST to create a sustainable compliance program that improves efficiency without weakening assurance?

  1. A

    Build a unified control framework that maps common controls to multiple regulatory, contractual, and certification requirements, then assign control ownership and evidence sources centrally

  2. B

    Prioritize only the most punitive regulation and defer lower-risk compliance obligations until customers specifically request evidence

  3. C

    Outsource all compliance activities to the internal audit function so business and security teams can focus on operations

  4. D

    Purchase a governance, risk, and compliance (GRC) tool and migrate all compliance records into it before rationalizing controls or accountability

Show answer and explanation

Correct answer: A

Explanation

The most effective first action is to establish a unified or common control framework that maps overlapping requirements across standards, regulations, and contracts. In a CCISO context, this demonstrates strategic governance, efficient compliance management, and alignment of assurance activities with business expansion. Framework mapping reduces duplicate testing, clarifies control ownership, and enables reusable evidence, which directly addresses audit fatigue while preserving assurance. This approach is consistent with recognized best practices in governance and assurance, including the principle of management responsibility for controls, internal audit independence under the three-lines model, and cross-framework control harmonization commonly used with ISO/IEC 27001, SOC 2, PCI DSS, and privacy compliance programs. A GRC tool may be valuable later, but it should enable a well-designed compliance operating model rather than define it.

  • A. Correct.

    This is the best first step because it addresses the root cause of audit fatigue: duplicated control testing and fragmented evidence collection. A unified control framework, sometimes called a common control framework, maps one set of controls to multiple obligations such as ISO/IEC 27001 Annex A controls, SOC 2 Trust Services Criteria, PCI DSS requirements, and applicable privacy obligations. Central assignment of control owners and evidence sources improves consistency, reduces redundant work, and strengthens defensibility during audits and regulatory inquiries. This approach aligns with widely accepted compliance and governance practices that emphasize control rationalization, traceability, and clear accountability.

  • B. Incorrect.

    This is incorrect because compliance programs must address the full set of applicable legal, regulatory, and contractual obligations, not just the ones with the harshest penalties. Deferring obligations until a customer asks for evidence creates unmanaged compliance risk and can lead to failed audits, contractual breaches, or regulatory findings. It also reflects a reactive rather than risk-informed governance model.

  • C. Incorrect.

    This is incorrect because internal audit provides independent assurance and should not own or operate the compliance program on behalf of management. Management, including business and security control owners, remains responsible for implementing and maintaining controls. Moving all compliance work to internal audit would compromise independence and conflict with common governance models, including the three-lines approach.

  • D. Incorrect.

    This is incorrect because a GRC platform can support scalability, workflow, and evidence management, but technology should not come before control rationalization and governance design. If the organization automates a fragmented compliance process without first establishing a unified control framework, ownership model, and evidence strategy, it may simply institutionalize inefficiency.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam