712-50 exam dumps

712-50 practice question 405 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 405

Single answerAssess and adjust security resources to ensure they support the organization's strategic objectives

A newly appointed CISO is reviewing the security program after the organization shifted its three-year strategy from operating mostly on-premises systems to launching digital customer services in multiple regions using cloud platforms and third-party development partners. The board has not increased the overall security budget, but it expects faster product delivery, improved resilience, and demonstrable regulatory compliance. The current security team is heavily staffed for perimeter device administration and legacy data center operations, while cloud architecture reviews, vendor risk management, and application security testing are understaffed. Which action should the CISO take FIRST to ensure security resources are aligned with the organization's strategic objectives?

  1. A

    Reallocate security resources based on a formal risk and business alignment assessment, shifting funding and staff toward cloud security, third-party risk, and secure development while defining metrics tied to business outcomes

  2. B

    Request an immediate across-the-board budget increase so all existing security functions can be preserved while new strategic capabilities are added

  3. C

    Maintain the current staffing model for operational stability and ask business units to absorb security responsibilities for cloud and vendor oversight

  4. D

    Prioritize additional investment in legacy perimeter controls because they are already mature and easier to justify through historical incident data

Show answer and explanation

Correct answer: A

Explanation

The key principle is that security leadership must align people, budget, and capabilities to the organization's strategic direction, not simply preserve legacy structures. In this scenario, the enterprise strategy has shifted toward cloud-based digital services and reliance on third parties, so the CISO should first perform and act on a business-aligned risk and capability assessment. That assessment should consider strategic objectives, changing threat exposure, regulatory requirements across regions, operating model changes, and current control maturity. From there, the CISO should reallocate staff and funding from lower-priority legacy activities toward cloud security architecture, secure SDLC support, third-party risk management, and metrics that show support for resilience, compliance, and product delivery. This approach is consistent with widely accepted practices in governance and resource management reflected in frameworks such as NIST Cybersecurity Framework 2.0 Govern function, NIST SP 800-53 control families related to planning and risk management, ISO/IEC 27001 resource and leadership requirements, and enterprise governance principles emphasizing alignment of security investments to business objectives and risk appetite.

  • A. Correct.

    This is the best answer because it directly addresses the core leadership responsibility of aligning security resources with enterprise strategy. A formal assessment of business objectives, risk exposure, regulatory obligations, and capability gaps allows the CISO to re-prioritize limited resources toward areas that now matter most: cloud security, third-party risk, and application security. Tying the reallocation to measurable business outcomes, such as release velocity with security gates, control coverage in cloud environments, vendor due diligence completion, and resilience metrics, helps demonstrate governance and value to executive leadership and the board.

  • B. Incorrect.

    This is plausible because additional budget may indeed be needed over time. However, it is not the best FIRST action because the scenario states the board has not increased the overall budget. A chief information security officer should first demonstrate disciplined resource optimization and strategic prioritization before seeking more funding. Simply requesting more money without showing a reallocation plan may be viewed as weak governance and poor business alignment.

  • C. Incorrect.

    This is incorrect because it offloads accountability for security capabilities that require enterprise oversight, such as cloud governance and third-party risk management. While federated security models can work, the CISO remains responsible for ensuring appropriate governance, standards, and assurance. Keeping a legacy-heavy staffing model despite a strategic shift creates misalignment and increases risk in the areas most critical to the business strategy.

  • D. Incorrect.

    This is incorrect because it prioritizes historical comfort over current strategic need. Legacy perimeter controls may still be necessary, but the organization's risk profile has changed with cloud adoption, digital services, and partner development. Continuing to overinvest in mature legacy controls while underinvesting in cloud, application, and vendor risk capabilities is a common misallocation error when security programs fail to evolve with business transformation.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam