712-50 Question 399
Single answerIdentify and consult with key stakeholders to ensure understanding of organization's objectivesA newly hired CISO is asked to build a three-year security strategy for a global manufacturing company that is expanding into direct-to-consumer digital sales. The board is concerned about cyber risk, the COO is focused on production uptime, the CFO is driving cost optimization, and the Chief Legal Officer is preparing for new privacy obligations in multiple regions. The CISO discovers that prior security investments were selected mainly by the IT department without business input, resulting in overlapping tools and poor executive support. What should the CISO do FIRST to ensure the security strategy is aligned with the organization's objectives?
- A
Conduct stakeholder interviews with business and functional leaders to identify strategic objectives, risk tolerance, and critical success factors before defining security priorities
- B
Benchmark the current security program against industry peers and adopt the most common controls to accelerate maturity
- C
Prioritize investments that close the largest number of technical vulnerabilities identified in recent infrastructure assessments
- D
Develop a target architecture based on zero trust principles and present it to executives for approval as the foundation of the strategy
Show answer and explanation
Correct answer: A
Explanation
This question tests a core CCISO competency: ensuring that security leadership begins with business alignment through stakeholder engagement. At the executive level, the CISO must identify and consult with key stakeholders, such as the board, business unit leaders, operations, finance, legal, privacy, and IT, to understand enterprise strategy, performance goals, regulatory obligations, and risk appetite. Only then can the CISO define a security strategy that supports business outcomes such as resilient manufacturing operations, digital revenue growth, cost-effective control design, and regional compliance.
This approach is consistent with widely accepted governance and risk management practices. COBIT emphasizes aligning IT and security-related objectives with enterprise goals. NIST Cybersecurity Framework 2.0 highlights governance, organizational context, stakeholder expectations, and risk management strategy as foundational inputs. ISO/IEC 27001 and ISO/IEC 27014 also reinforce that information security governance should be driven by organizational objectives and leadership direction. In practice, stakeholder consultation often includes structured interviews, strategy workshops, review of business plans, risk appetite discussions, and validation of critical business services before prioritizing initiatives, metrics, and investments.
- A. Correct.
Correct. The first step is to identify and consult with key stakeholders so the CISO understands business strategy, operational priorities, compliance drivers, and executive risk appetite. In this scenario, different leaders have materially different objectives: revenue growth, uptime, cost control, and legal compliance. A security strategy that is not informed by these perspectives is unlikely to gain support or align with enterprise goals. This reflects executive-level security governance practice: security should enable business objectives and be prioritized based on enterprise risk and stakeholder needs.
- B. Incorrect.
Incorrect. Peer benchmarking can be useful later as an input for maturity targets or program justification, but it does not replace understanding the organization's own strategy and stakeholder priorities. A control set that is common in the industry may still be misaligned with this company's expansion plans, manufacturing dependency, or legal obligations. Choosing controls because peers use them is a common mistake when strategic alignment has not yet been established.
- C. Incorrect.
Incorrect. Technical vulnerabilities matter, but beginning with vulnerability remediation data focuses the strategy too narrowly on IT findings rather than enterprise objectives. The scenario highlights business misalignment, overlapping tools, and lack of executive support. A CISO at the executive level must first understand which business services are most critical, what level of risk the organization is willing to accept, and where security can best support growth and resilience. Otherwise, the program may optimize technical hygiene without addressing strategic needs.
- D. Incorrect.
Incorrect. Zero trust may be an appropriate architectural direction, but proposing a target architecture before consulting stakeholders risks repeating the exact problem described in the scenario: solutions selected without business input. Architecture should be derived from agreed business priorities, operating model needs, regulatory requirements, and risk tolerance. Presenting a predefined architecture too early can reduce executive buy-in and create the perception that security is technology-led rather than business-led.