712-50 exam dumps

712-50 practice question 392 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 392

Single answerStrategic Planning (6 questions)

A newly appointed CISO is preparing a three-year security strategy for a global manufacturing company that is expanding through acquisitions and increasing its use of cloud-based operational systems. The board has stated that the company's top business priorities are maintaining production uptime, accelerating integration of acquired businesses, and meeting customer and regulatory expectations. The current security program consists of disconnected technical projects driven by audit findings, with no clear linkage to business outcomes. What should the CISO do FIRST to build an effective strategic security plan that is most likely to gain sustained executive support?

  1. A

    Create a prioritized security roadmap by mapping business objectives, risk appetite, and critical business processes to a target security capability model

  2. B

    Immediately launch a company-wide zero trust transformation program to modernize identity, network, and endpoint controls before the next budget cycle

  3. C

    Benchmark the security budget against industry peers and request an equivalent percentage increase to address known control gaps

  4. D

    Expand technical vulnerability management and patching metrics so the board can track remediation performance monthly

Show answer and explanation

Correct answer: A

Explanation

For CCISO-level strategic planning, the most effective starting point is to build a security strategy that is explicitly derived from business strategy, enterprise risk management, and the organization's critical processes and dependencies. In this scenario, the business priorities are clear: production uptime, rapid post-acquisition integration, and regulatory/customer trust. Therefore, the CISO should first translate those priorities into security capabilities, target state requirements, and a phased roadmap. This is consistent with widely accepted practices in governance and strategic planning, including alignment principles found in frameworks such as NIST Cybersecurity Framework (governance, business context, risk management strategy), ISO/IEC 27001 and 27014 governance concepts, and COBIT's emphasis on aligning IT and security objectives with enterprise goals. Once that alignment is established, the CISO can justify initiatives such as zero trust, integration security standards, resilience improvements, or budget increases as components of a coherent strategy rather than as disconnected projects.

  • A. Correct.

    Correct. In strategic planning, the CISO's first step should be to align the security strategy with enterprise objectives, risk tolerance, and the organization's most critical business services and processes. This creates a defensible roadmap tied to outcomes the board cares about, such as uptime, acquisition integration, and compliance. A target capability model helps translate business priorities into strategic initiatives, sequencing investments based on value and risk reduction rather than on isolated technical issues. This approach is also more likely to secure executive sponsorship because it frames security as a business enabler.

  • B. Incorrect.

    Incorrect. Zero trust may be a valid strategic initiative in some environments, but launching it immediately would be premature without first establishing alignment to business priorities, architectural constraints, acquisition plans, and risk appetite. A common misconception is that adopting a popular security model is itself a strategy. In reality, zero trust is an approach or architectural direction, not a substitute for an enterprise-aligned strategic planning process.

  • C. Incorrect.

    Incorrect. Budget benchmarking can be useful as supporting data, but asking for an industry-average increase is not the best first step. Peer comparisons do not prove that a given investment fits this organization's strategy, threat environment, operational dependencies, or acquisition agenda. This option reflects the misconception that security maturity can be achieved primarily by matching spending levels rather than by aligning investments to business risk and strategic objectives.

  • D. Incorrect.

    Incorrect. Improving vulnerability and patching metrics may strengthen operational oversight, but it does not address the core strategic problem: the security program is fragmented and not linked to business outcomes. Boards typically need a business-based view of risk, resilience, and strategic enablement rather than a narrow set of technical performance indicators. This option confuses operational management with enterprise security strategy.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam