712-50 exam dumps

712-50 practice question 393 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 393

Single answerStrategic Planning (6 questions)

A newly appointed CISO is developing a three-year information security strategy for a global manufacturing company that is expanding through acquisitions and increasing its use of cloud-based industrial analytics. The board has stated that growth, operational resilience, and regulatory readiness are the top business priorities. The current security program is fragmented: acquired business units use different controls, security spending is reactive, and security metrics focus mainly on tool activity rather than business outcomes. Which action should the CISO take FIRST to build a strategic plan that is most likely to gain executive support and remain effective over the planning horizon?

  1. A

    Create a roadmap that standardizes security technologies across all business units and mandates immediate consolidation onto a single toolset

  2. B

    Develop a risk-based security strategy that maps security objectives to business goals, defines target capabilities, and sequences initiatives based on enterprise risk and value

  3. C

    Benchmark the security program against industry peers and adopt the control set used by the most mature competitor

  4. D

    Launch an enterprise-wide awareness campaign to improve security culture before requesting additional budget for strategic initiatives

Show answer and explanation

Correct answer: B

Explanation

For CCISO-level strategic planning, the starting point is not tools, isolated projects, or generic benchmarking. It is the creation of a business-aligned, risk-based security strategy that supports enterprise objectives and translates them into a multi-year capability roadmap. In this scenario, the board has already identified the strategic drivers: growth through acquisition, operational resilience, and regulatory readiness. The CISO should therefore assess enterprise risk in that context, define the target security capabilities needed to support integration, cloud adoption, and resilient operations, and prioritize initiatives based on business impact, risk reduction, dependencies, and available resources.

This reflects widely accepted good practice. NIST Cybersecurity Framework emphasizes understanding organizational context, business requirements, and risk when establishing and improving cybersecurity outcomes. ISO/IEC 27001 requires consideration of organizational context, interested parties, and risk treatment in establishing an information security management system. COBIT also stresses alignment of IT and security governance with enterprise goals and value delivery. At the executive level, strategic planning should produce a defensible roadmap, meaningful business-oriented metrics, and governance mechanisms that allow leadership to adjust priorities as the business evolves.

  • A. Incorrect.

    This is not the best first action. Standardizing technologies may eventually be appropriate, especially after acquisitions, but starting with tool consolidation is solution-led rather than strategy-led. It risks overlooking business priorities, differing risk profiles, integration constraints, and regulatory obligations across acquired entities. In strategic planning, the CISO should first establish how security will support enterprise objectives and what capabilities are required before selecting or rationalizing technologies.

  • B. Correct.

    This is the best answer. A CISO-level strategic plan should begin with business alignment and a risk-based view of the enterprise. By mapping security objectives to growth, resilience, and compliance goals, the CISO can show executives how security enables the business rather than operating as a standalone technical function. Defining target capabilities creates a future-state model, and sequencing initiatives by risk reduction, business value, and feasibility supports funding decisions and governance over a multi-year horizon. This approach is consistent with executive-level security leadership and recognized practices in frameworks such as NIST CSF, COBIT, and ISO/IEC 27001, which emphasize aligning security activities with organizational context, risk, and objectives.

  • C. Incorrect.

    This is a plausible but incorrect choice. Benchmarking can be useful as an input to planning, especially to identify capability gaps or justify investment levels. However, copying a competitor's control set does not ensure alignment with this organization's acquisition strategy, operational technology exposure, cloud adoption, or regulatory environment. Strategic planning at the CISO level should be tailored to the organization's own risk appetite, business model, and strategic goals rather than based primarily on peer imitation.

  • D. Incorrect.

    This is a worthwhile supporting initiative but not the first strategic step. Security culture and awareness are important program elements, yet beginning with a campaign does not address the core issue: the company lacks a unified, business-aligned security strategy. Without a defined target state, governance model, and prioritized roadmap, awareness efforts may be disconnected from the most significant enterprise risks and may not justify long-term investment.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam