712-50 Question 395
Single answerA global manufacturing company has grown through acquisitions and now operates separate ERP systems, multiple identity stores, inconsistent network segmentation between plants and corporate offices, and different security tools in each region. The board has approved a business strategy to standardize supply-chain operations and increase secure partner connectivity within 18 months. The CISO has been asked to design an enterprise information security architecture (EISA) that supports this transformation without disrupting production. Which action should the CISO take FIRST to ensure the security architecture is aligned with business processes, technology, people, and operations?
- A
Define a target-state security architecture based on business capabilities, critical data flows, trust boundaries, and integration requirements, then use it to prioritize a phased roadmap
- B
Deploy a single enterprise security toolset across all regions immediately to reduce architectural inconsistency and improve centralized visibility
- C
Mandate one global network segmentation standard for all plants and offices before reviewing operational dependencies to accelerate standardization
- D
Begin by replacing all regional identity stores with a centralized directory so that access control can be standardized before broader architecture work
Show answer and explanation
Correct answer: A
Explanation
The best first action is to define a target-state enterprise security architecture that is explicitly derived from business strategy and operational realities. In CCISO-level practice, architecture is not just a technology stack decision; it is the structured alignment of business processes, applications, infrastructure, networks, people, and operating models with security objectives. In this scenario, the organization must support supply-chain standardization and secure partner connectivity while preserving production continuity. That requires the CISO to assess the current state, map critical business capabilities and data flows, identify trust boundaries between plants, corporate environments, and external partners, and then create a phased roadmap for controls, integration, and governance.
This approach is consistent with well-established architecture and security practices found in frameworks such as SABSA, TOGAF, NIST Cybersecurity Framework, and NIST SP 800-160 principles for systems security engineering. These emphasize deriving architecture from business requirements, understanding system context and dependencies, and implementing change through planned transition states rather than isolated control deployments. Tool consolidation, segmentation, and identity modernization may all be valid initiatives, but they should follow from the target-state architecture and gap analysis, not precede them.
- A. Correct.
Correct. In an enterprise architecture context, the first step is to understand and model the business strategy, business capabilities, critical processes, data flows, and trust relationships, then define a target-state architecture that aligns security with those realities. This approach allows the CISO to sequence change in a way that supports supply-chain standardization, partner connectivity, and plant uptime. It reflects sound architecture practice: current-state assessment, target-state definition, gap analysis, and roadmap development.
- B. Incorrect.
Incorrect. Standardizing tools may eventually be part of the roadmap, but leading with tooling is a common mistake. Tools do not by themselves resolve misalignment across business processes, identity models, network trust zones, plant operations, and acquired environments. Immediate deployment without architectural analysis can increase operational risk and create expensive rework.
- C. Incorrect.
Incorrect. Network segmentation is important, especially for manufacturing and operational technology environments, but imposing a universal standard before understanding plant-specific dependencies, production constraints, and business integration needs may disrupt operations. Architecture should be risk-based and business-aligned rather than driven by a single technical control in isolation.
- D. Incorrect.
Incorrect. Identity consolidation is often a major component of enterprise security architecture, particularly where multiple identity stores exist. However, doing it first without defining the broader target architecture, business process requirements, partner access model, and phased transition plan risks solving only one domain while creating integration issues elsewhere. Identity should be addressed as part of the overall architectural roadmap.