712-50 exam dumps

712-50 practice question 404 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 404

Single answerAssess and adjust security resources to ensure they support the organization's strategic objectives

A newly appointed CISO is reviewing the security program after the company approved a 3-year strategy to expand its digital sales channels and migrate several customer-facing services to the cloud. The security budget has remained flat for two years, and most of the team is still assigned to maintaining legacy on-premises controls that support declining business units. Business executives are concerned that security is slowing transformation initiatives, while the board expects risk reporting to show clear alignment to strategic objectives. Which action should the CISO take FIRST to assess and adjust security resources so they better support the organization's strategy?

  1. A

    Reallocate security budget and staff based on a risk-based capability assessment tied to the new business strategy, including cloud security, application security, and third-party oversight needs

  2. B

    Request an immediate budget increase for additional headcount because digital transformation and cloud migration inherently increase cyber risk

  3. C

    Maintain current resource allocation until the cloud migration is complete so that legacy operations remain fully protected during the transition

  4. D

    Outsource most operational security activities to a managed service provider to free internal staff for strategic projects

Show answer and explanation

Correct answer: A

Explanation

In CCISO practice, senior security leadership is expected to align security investments, staffing, and operating models with enterprise objectives rather than simply defending historical structures. The best first step is a risk-based capability and resource assessment mapped to business strategy. This enables the CISO to determine whether current personnel, tools, and budget allocations support the company's digital expansion, cloud adoption, and board reporting needs. It also creates the foundation for later actions such as budget requests, upskilling, automation, or selective outsourcing. This approach is consistent with widely recognized guidance from NIST CSF 2.0, which emphasizes governance, organizational context, and aligning cybersecurity activities with mission objectives, as well as COBIT principles around aligning IT and security resources to enterprise goals. From an executive leadership perspective, the CISO should demonstrate that resources are being shifted according to business priorities and risk appetite, not merely increased or preserved based on legacy operations.

  • A. Correct.

    Correct. The first priority is to assess current security capabilities and resource allocation against the organization's revised strategic direction and risk profile. A risk-based capability assessment lets the CISO identify where existing staff, budget, and controls no longer align with business priorities, then reassign resources to areas that directly support digital growth, such as cloud governance, secure architecture, DevSecOps, identity, and vendor risk management. This approach also supports defensible reporting to executives and the board because it links spending and staffing decisions to strategic objectives and business risk.

  • B. Incorrect.

    Incorrect. Although transformation can increase or change risk exposure, immediately asking for more budget is premature without first demonstrating how current resources are misaligned and what capability gaps exist. Executive leadership and boards generally expect the CISO to optimize existing resources before requesting additional funding. A business-aligned assessment provides the evidence needed to justify future investment if required.

  • C. Incorrect.

    Incorrect. This preserves historical allocations rather than aligning security resources with the organization's current strategic objectives. While legacy environments still require protection, keeping resources unchanged during a major transformation is likely to deepen gaps in cloud, application, and third-party risk areas. The misconception is that stability in old environments should take precedence over strategic business enablement without re-evaluating relative risk and value.

  • D. Incorrect.

    Incorrect. Managed services may be part of a later optimization strategy, but outsourcing most operations is not the best first step. Without first assessing which capabilities are strategic, which are commodity, and what risks must be retained internally, the organization could outsource critical functions inappropriately or fail to solve the core alignment problem. This option reflects a common mistake of treating sourcing as a substitute for strategy.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam