712-50 exam dumps

712-50 practice question 398 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 398

Single answerIdentify and consult with key stakeholders to ensure understanding of organization's objectives

A newly appointed CISO is asked to develop a three-year security strategy for a global manufacturer that is expanding into direct-to-consumer digital sales while also modernizing its factories with connected operational technology (OT). The board has stated that growth, supply chain resilience, regulatory compliance, and protection of intellectual property are top priorities. However, business unit leaders disagree on which risks matter most, and prior security initiatives were criticized for being too IT-centric and disconnected from business outcomes. What should the CISO do FIRST to ensure the security strategy is aligned with the organization's objectives?

  1. A

    Conduct targeted consultations with executive and business stakeholders to validate strategic objectives, risk appetite, critical processes, and success measures before defining the security roadmap

  2. B

    Start with a comprehensive vulnerability assessment across corporate IT and OT environments to establish a technical baseline for the strategy

  3. C

    Adopt a leading security framework and map all planned initiatives to its control domains so the program reflects industry best practice

  4. D

    Draft a security strategy based on the board's stated priorities and present it for approval, since board direction is the most authoritative source of organizational objectives

Show answer and explanation

Correct answer: A

Explanation

The best answer is to engage key stakeholders first to ensure the CISO understands the organization's objectives in operational and strategic terms. In CCISO practice, security strategy should be business-driven, risk-informed, and developed in consultation with stakeholders who define priorities, own processes, or are accountable for risk. This includes senior executives, business unit leaders, legal/compliance, operations, finance, and technology leadership. A common governance principle in sources such as COBIT and NIST guidance is that enterprise objectives drive alignment goals, which in turn drive security and control activities. Similarly, ISO/IEC 27001 emphasizes understanding the organization and its context, as well as the needs and expectations of interested parties, before defining the scope and direction of the information security management system. In this scenario, stakeholder consultation is the critical first step because the challenge is not lack of technical data; it is lack of shared understanding of business objectives and priorities. Once those are clarified, the CISO can assess risk, choose appropriate frameworks, and build a roadmap with clear support from the business.

  • A. Correct.

    This is correct because the CISO's first responsibility is to understand and validate business objectives with the relevant stakeholders who own or influence them. In this scenario, the board has given high-level priorities, but business unit leaders have differing views and previous efforts failed because they were not grounded in business realities. Consulting with stakeholders such as the CEO, CFO, COO, general counsel, head of manufacturing, supply chain leadership, digital commerce leaders, and risk/compliance owners helps clarify strategic objectives, risk appetite, critical business services, and measurable outcomes. This creates the foundation for a security strategy that supports the enterprise rather than simply improving technical controls.

  • B. Incorrect.

    This is incorrect because a technical assessment is useful, but it should not be the first step when the problem is strategic alignment. Starting with vulnerabilities risks repeating the same IT-centric mistake described in the scenario. Without understanding the organization's objectives, business model changes, and stakeholder priorities, the CISO may collect data that does not answer the most important strategic questions or may overemphasize technical weaknesses that have limited business relevance.

  • C. Incorrect.

    This is incorrect because frameworks such as NIST Cybersecurity Framework, ISO/IEC 27001, or COBIT can help structure the program, but a framework is not a substitute for understanding the organization's unique business goals and stakeholder expectations. If the CISO selects and maps to a framework before engaging stakeholders, the resulting strategy may be compliant in form yet poorly aligned to growth plans, OT modernization, supply chain resilience, or intellectual property protection priorities.

  • D. Incorrect.

    This is incorrect because board priorities are important, but they are still high-level and may not capture operational dependencies, conflicting incentives, risk ownership, or the practical realities of implementation across business units. Presenting a draft strategy without first consulting key stakeholders would likely reinforce the perception that security is disconnected from the business. Effective security leadership requires translating board intent into an actionable enterprise strategy through stakeholder engagement and validation.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam