712-50 Question 396
Single answerA newly appointed CISO at a regional healthcare provider has been asked to support the organization's three-year strategy: expand telehealth services, form data-sharing partnerships with insurers, and reduce operating costs. External analysis shows patients increasingly expect mobile access to health data, competitors are marketing secure digital services, and regulators are increasing scrutiny of healthcare privacy and third-party data sharing. Internal analysis shows the security team is understaffed, third-party risk reviews are inconsistent, legacy identity systems delay patient onboarding, and current metrics focus mainly on blocked attacks rather than business outcomes. Which action should the CISO take FIRST to best align the information security program with the organization's objectives?
- A
Implement a broad set of advanced security tools to match competitors' security spending and demonstrate rapid maturity improvement
- B
Develop a risk-informed security roadmap that maps telehealth growth, partner integration, privacy obligations, and internal capability gaps to prioritized security initiatives and business-oriented metrics
- C
Increase the frequency of vulnerability scanning and report the number of critical findings closed each month to the board
- D
Delay major security changes until the telehealth platform is fully deployed so the business strategy is not disrupted
Show answer and explanation
Correct answer: B
Explanation
The key competency being tested is the CISO's ability to perform external and internal analysis and use the results to align the information security program with enterprise strategy. In this scenario, external analysis includes customer expectations for digital healthcare, competitive pressures, and the regulatory environment around privacy and data sharing. Internal analysis includes staffing constraints, weak third-party risk governance, legacy identity limitations, and poor performance measures. The best response is not a tactical control improvement or a tool purchase, but a strategic roadmap that prioritizes initiatives based on business goals, risk exposure, and organizational capability. This approach is consistent with widely accepted practices in security leadership and governance, including NIST CSF 2.0's emphasis on Govern and aligning cybersecurity outcomes to organizational context, ISO/IEC 27001 and 27014 principles around governance and business alignment, and enterprise risk management concepts that require security investments to support mission objectives, compliance needs, and stakeholder expectations.
- A. Incorrect.
This is incorrect because it focuses on technology acquisition and competitor imitation rather than alignment to business objectives and risk context. External analysis should inform strategy, but simply matching competitor spending does not ensure the organization is addressing its own market position, regulatory obligations, customer expectations, and internal constraints. This is a common mistake when security is treated as a technology function instead of a business enabler.
- B. Correct.
This is correct because it integrates both external and internal analysis into a security strategy that supports organizational goals. The organization is pursuing telehealth expansion, insurer data sharing, and cost reduction, while facing market pressure, regulatory scrutiny, and internal capability limitations. A risk-informed roadmap allows the CISO to prioritize initiatives such as identity modernization, third-party risk management, privacy controls, and meaningful performance measures tied to patient onboarding, partner trust, compliance exposure, and operational efficiency. This is the best first step because it creates strategic alignment before selecting specific projects or tools.
- C. Incorrect.
This is incorrect because it improves an operational control activity but does not address the broader alignment problem. Vulnerability management is important, but reporting closed findings is still largely a technical metric and does not directly connect security efforts to telehealth growth, third-party partnerships, privacy expectations, or business performance. Candidates may choose this because it appears measurable and actionable, but it is too narrow for the scenario.
- D. Incorrect.
This is incorrect because postponing security planning until after business deployment increases risk and undermines the organization's objectives. Security should be integrated early into strategic initiatives, especially where healthcare privacy, third-party sharing, and digital patient services are involved. Delaying action may create rework, compliance gaps, and weaker trust with patients and partners.