712-50 exam dumps

712-50 practice question 407 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 407

Single answerMonitor and update activities to ensure accountability and progress

A newly appointed CISO is overseeing a 12-month security transformation program that includes IAM modernization, vulnerability management improvements, and third-party risk enhancements. At the end of the second quarter, the board reports that status updates are inconsistent across workstreams, several milestones have slipped without documented approval, and it is unclear which executives are accountable for delayed deliverables. The CISO wants to improve oversight without creating excessive administrative overhead. Which action would BEST enable accountability and measurable progress across the program?

  1. A

    Implement a governance cadence with standardized KPI/KRI reporting, named business owners for each milestone, issue/risk escalation thresholds, and formal tracking of dependencies and approved schedule changes.

  2. B

    Require each project manager to submit narrative weekly email updates to the CISO and allow workstream leads to define their own success criteria based on local operational needs.

  3. C

    Delay further reporting changes until the annual budgeting cycle so that governance updates can be aligned with next year's strategic planning process.

  4. D

    Focus board reporting only on major incidents and audit findings, because operational milestone tracking is better handled informally within technical teams.

Show answer and explanation

Correct answer: A

Explanation

Effective monitoring and update activities in a security program require more than periodic status communication; they require governance structures that support accountability, traceability, and timely decision-making. In this scenario, the key issues are inconsistent reporting, undocumented milestone changes, and unclear ownership. The strongest response is to implement a formal governance cadence with standardized metrics, assigned accountable owners, dependency tracking, escalation triggers, and controlled approval of schedule changes. This reflects widely accepted program and governance practices found in enterprise security management, PMO disciplines, and control frameworks. For example, principles from COBIT emphasize governance objectives, performance monitoring, and accountability assignment; NIST guidance on risk management and cybersecurity governance similarly supports documented oversight, defined roles, and continuous monitoring of implementation progress. The best CISO response is therefore to create a lightweight but disciplined mechanism that makes progress measurable, ownership explicit, and deviations visible to decision-makers.

  • A. Correct.

    This is the best answer because it establishes the core management controls needed to monitor and update activities effectively: standardized reporting, explicit accountability, escalation criteria, dependency management, and formal change control for milestones. These mechanisms give leadership a consistent view of progress while ensuring that slippage is visible, owned, and addressed. This aligns with common program governance practices used in enterprise security initiatives and supports board-level oversight without relying on ad hoc status updates.

  • B. Incorrect.

    This is incorrect because narrative emails are difficult to aggregate, compare, and audit across multiple workstreams. Allowing each lead to define success differently undermines consistency and weakens accountability. A candidate might choose this because weekly updates sound proactive, but the approach does not create measurable, repeatable governance or clear ownership.

  • C. Incorrect.

    This is incorrect because the problem is current and operational, not something that should wait for a future planning cycle. Deferring governance improvements allows accountability gaps and schedule slippage to continue. Someone might choose this option thinking strategic alignment is important, but effective CISOs address monitoring weaknesses as soon as they impair execution.

  • D. Incorrect.

    This is incorrect because limiting reporting to incidents and audits ignores the need to manage strategic security program execution. Boards and executives need visibility into milestone status, risks, dependencies, and ownership when major transformation efforts are underway. This option reflects the misconception that security governance is only about reactive events rather than delivery of planned risk-reduction outcomes.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam