712-50 Question 400
Single answerA newly appointed CISO joins a global manufacturing company that is shifting from traditional product sales to digitally enabled services, including connected equipment, predictive maintenance, and expanded third-party integration. The board has approved aggressive revenue targets for these initiatives over the next three years, but the current information security program is still centered on annual compliance audits, perimeter controls, and reactive incident handling. The CEO asks the CISO to present a forward-looking strategic plan that repositions security as a business enabler while supporting operational needs across factories, cloud platforms, and partner ecosystems. Which action should the CISO take FIRST to build the most effective strategic plan?
- A
Define a security vision aligned to the organization's digital business strategy, then translate it into a multi-year roadmap with measurable objectives, target capabilities, and business-relevant outcomes
- B
Start by selecting and deploying advanced security technologies for OT, cloud, and third-party monitoring so the strategy is based on modern controls
- C
Use the latest regulatory requirements as the primary driver of the strategy because compliance obligations provide the clearest security priorities
- D
Focus first on rewriting all security policies and standards so business units have a complete governance baseline before strategic planning begins
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because CCISO-level leadership requires the CISO to create a forward-looking security strategy that is business-driven, risk-informed, and measurable. In a transforming enterprise, the security program must move beyond operational control maintenance and compliance management to define how security will enable strategic objectives over a multi-year horizon. Best practices from frameworks such as NIST CSF, COBIT, and ISO/IEC 27001 support this approach by emphasizing alignment between business context, governance, risk management, target-state capabilities, and continual improvement. At the executive level, the strategic plan should articulate a vision, define goals and objectives, identify capability gaps, prioritize initiatives, assign metrics and targets, and demonstrate how security supports resilience, trust, and growth. Tool selection, compliance mapping, and policy updates are all important, but they should follow, not precede, the definition of an aligned strategic vision and roadmap.
- A. Correct.
Correct. A CISO's strategic plan should begin with business alignment: understanding the organization's future direction, risk appetite, operating model, and strategic objectives. From there, the CISO can define a vision for the security program and create a multi-year roadmap with clear goals, capability targets, milestones, and metrics tied to business outcomes such as resilient digital services, trusted partner integration, and secure innovation. This is the most appropriate first step because it ensures security supports operational needs rather than operating as a disconnected technical function.
- B. Incorrect.
Incorrect. Modern technologies may be part of the eventual roadmap, but selecting tools first is a common mistake. Technology decisions should follow strategy, not define it. Without first identifying business priorities, target-state capabilities, and risk-based objectives, the organization may overspend on tools that do not address the most critical operational or strategic needs.
- C. Incorrect.
Incorrect. Compliance is important, but a visionary strategic plan for the security program should not be driven primarily by regulatory requirements. A compliance-led approach tends to be backward-looking and minimum-baseline oriented. In this scenario, the company is transforming its business model, so the strategy must account for digital growth, operational resilience, third-party risk, and innovation enablement in addition to legal and regulatory obligations.
- D. Incorrect.
Incorrect. Policies and standards are necessary governance instruments, but rewriting them first does not establish strategic direction. Governance documentation should be updated after the CISO defines the future-state vision, priorities, and implementation roadmap. Beginning with policy revision can lead to administrative effort without resolving the larger issue of aligning security to business transformation.