712-50 Question 4
Single answerGovernance (6 questions)A newly appointed CISO at a global manufacturing company discovers that security policies are fragmented across business units, risk treatment decisions are made inconsistently, and major security investments are approved without a clear link to business objectives. The board has asked for a governance improvement plan that will give executives better oversight while preserving accountability within the business. Which action should the CISO take FIRST to establish effective information security governance?
- A
Implement a centralized approval process requiring the CISO to sign off on all security-related technology purchases across all business units
- B
Establish an enterprise information security governance framework that defines decision rights, reporting, risk tolerance alignment, and accountability to business objectives
- C
Launch an enterprise-wide security awareness campaign so business leaders better understand their responsibilities for cyber risk
- D
Standardize technical controls across all regions before revising policies so the organization has a common security baseline
Show answer and explanation
Correct answer: B
Explanation
Information security governance is a leadership and oversight function, not merely a technical management activity. In this scenario, the symptoms, fragmented policies, inconsistent risk treatment, and investments not tied to business objectives, indicate that the organization lacks a formal governance structure. The CISO should first establish an enterprise governance framework that defines authority, accountability, reporting, and alignment to business strategy. This approach is consistent with widely accepted governance principles in frameworks such as COBIT, ISO/IEC 27014, and ISO/IEC 27001, which emphasize aligning information security with organizational objectives, assigning roles and responsibilities, and ensuring oversight by senior leadership. The board's role is to provide direction and oversight, while management executes within defined decision rights and risk parameters. After governance is established, the organization can rationally update policies, improve awareness, and standardize controls in a way that supports enterprise goals.
- A. Incorrect.
This is not the best first step. While centralized approval may increase control, it can undermine the principle that business management retains ownership of risk and accountability for business decisions. Governance should define who has authority, how decisions are made, and how security aligns with organizational objectives before imposing approval mechanisms. A CISO-led sign-off model can also create bottlenecks and blur lines between governance, management, and operational execution.
- B. Correct.
This is correct. Effective security governance begins with a formal framework that aligns security with enterprise strategy, clarifies decision rights, establishes accountability, defines reporting and escalation paths, and integrates risk tolerance set by leadership. In this scenario, the primary problem is not lack of isolated controls but lack of consistent governance structure. Creating the framework first enables subsequent policy, investment, and oversight improvements to be coherent and business-driven.
- C. Incorrect.
This is useful but not the first governance action. Awareness can improve understanding, but training alone does not resolve structural governance failures such as unclear accountability, fragmented policy authority, and disconnected investment decisions. Without a defined governance model, awareness efforts may be inconsistent or fail to change how decisions are actually made.
- D. Incorrect.
This is a common but incorrect operational response. Standardizing controls may reduce technical variance, but it does not by itself establish governance. Governance must precede broad control harmonization so that control decisions reflect enterprise priorities, legal and regulatory requirements, risk appetite, and business ownership. Otherwise, the organization may standardize the wrong controls or impose inconsistent requirements without executive buy-in.