712-50 Question 401
Single answerA newly appointed CISO joins a global manufacturing company that is shifting from traditional product sales to connected, subscription-based services. The board has approved an aggressive three-year digital transformation strategy involving IoT-enabled products, expanded cloud adoption, and increased data-sharing with third-party service providers. The current information security program is largely compliance-driven, focused on annual audits and perimeter controls, and is viewed by business leaders as slowing innovation. The CEO asks the CISO to present a forward-looking security strategic plan that supports the transformation while improving resilience and business trust. Which action should the CISO take FIRST to build the most effective strategic plan?
- A
Develop a three-year security roadmap aligned to business strategy by identifying critical digital initiatives, defining target security capabilities, and establishing measurable objectives tied to business outcomes such as product trust, resilience, and third-party risk reduction
- B
Begin by selecting and deploying the latest security technologies for IoT, cloud, and zero trust so the organization can quickly modernize its defenses before business adoption accelerates
- C
Expand the existing compliance program by adding more policies, audit checkpoints, and mandatory approvals to ensure all new digital initiatives meet regulatory obligations before launch
- D
Benchmark the security budget against industry peers and request a larger funding allocation so the security team can scale resources in anticipation of future transformation needs
Show answer and explanation
Correct answer: A
Explanation
The best first action is to create a business-aligned, forward-looking security strategy that defines how the information security program will support the organization's operational and strategic goals. In CCISO practice, senior security leadership is expected to move beyond tactical controls and compliance management to establish a vision, mission, goals, objectives, and performance targets that support enterprise transformation. In this case, the organization's move to connected services, cloud platforms, and third-party ecosystems changes its risk profile and requires a corresponding evolution in security capabilities.
A strong strategic plan typically includes: understanding enterprise strategy and risk appetite; identifying future business processes and digital dependencies; defining target capabilities such as product security, cloud governance, third-party risk management, detection and response, and resilience; prioritizing initiatives over a multi-year horizon; and establishing measurable outcomes tied to business value. Examples of such targets might include reduction in supplier risk exposure, improved secure product release maturity, faster incident recovery, or increased customer trust through secure-by-design practices.
This approach is consistent with widely accepted practices in strategic security leadership and governance frameworks. NIST Cybersecurity Framework emphasizes aligning cybersecurity activities to business requirements, risk tolerance, and resources. COBIT reinforces governance alignment between enterprise goals and IT/security objectives. ISO/IEC 27001 and ISO/IEC 27014 also support establishing information security direction in line with organizational purpose and governance needs. For a CCISO, the key distinction is that strategy starts with business enablement and future-state capability planning, not with tools, audits, or budget alone.
- A. Correct.
Correct. A strategic security plan should start with clear alignment to organizational direction, operating model changes, and value creation goals. In this scenario, the company is changing its business model, technology landscape, and risk exposure. The CISO's first step should be to translate those business changes into a future-state security vision, capability roadmap, and measurable targets. This approach positions security as a business enabler rather than a control function and reflects executive-level planning expected of a CCISO.
- B. Incorrect.
Incorrect. Modern technologies may be part of the eventual roadmap, but choosing tools first is a common tactical mistake. Without first understanding business priorities, target-state architecture, risk appetite, and success measures, technology investments may be fragmented, redundant, or misaligned with strategic objectives.
- C. Incorrect.
Incorrect. Compliance remains important, but a strategy centered primarily on more policies and approvals would reinforce the perception that security is obstructing innovation. It addresses minimum obligations rather than building a visionary, business-aligned program that enables secure digital growth and resilience.
- D. Incorrect.
Incorrect. Budget benchmarking can support planning, but it should not come before defining strategy, business objectives, and required capabilities. Requesting more funding without a clearly articulated strategic vision and measurable outcomes is less likely to gain sustained executive support and may lead to inefficient spending.