712-50 Question 408
Single answerFinance (5 questions)A newly appointed CISO is preparing the security budget for the next fiscal year. The board has asked for a funding recommendation between two competing initiatives: (1) deploying privileged access management (PAM) for administrators and (2) expanding cyber awareness training for all staff. The organization experienced two minor phishing-related incidents last year with limited financial impact, but an internal audit found excessive administrator privileges across critical financial systems. The CFO wants a defensible, business-focused recommendation tied to financial decision-making. Which approach should the CISO use FIRST to justify the investment?
- A
Recommend the initiative with the lowest upfront acquisition cost so the security budget remains under target
- B
Perform a risk-based cost-benefit analysis using factors such as likelihood, impact, and expected loss reduction for each initiative
- C
Select the initiative most strongly preferred by the IT operations team because they will implement and maintain it
- D
Recommend awareness training because it affects the largest number of employees and therefore must provide the greatest value
Show answer and explanation
Correct answer: B
Explanation
In CCISO finance scenarios, the key responsibility is to translate security needs into business terms that executives and boards can evaluate. The best first step is a risk-based cost-benefit analysis, often supported by concepts such as annualized loss expectancy, probable frequency of loss events, control effectiveness, residual risk, and total cost of ownership. While exact formulas may vary by organization, the principle is consistent with established risk management and governance practices in frameworks such as NIST SP 800-30 for risk assessment, NIST CSF governance and risk management outcomes, and ISO/IEC 27005 for information security risk management. In this case, the internal audit finding around excessive administrator privileges in critical financial systems suggests a potentially high-impact exposure, even if recent phishing incidents were more visible. A mature CISO should recommend investment based on expected reduction in business risk and financial loss, not popularity, implementation preference, or lowest initial cost.
- A. Incorrect.
This is incorrect because choosing solely on upfront cost ignores expected risk reduction, potential loss exposure, implementation benefits, and total cost of ownership. In CCISO-level financial decision-making, the CISO is expected to justify spending based on business risk and value, not just lowest purchase price. A less expensive control may deliver substantially less reduction in financial exposure.
- B. Correct.
This is correct because a risk-based cost-benefit analysis is the most defensible first step when prioritizing security investments. The CISO should compare each initiative in terms of probable loss exposure, control effectiveness, implementation and operating costs, and alignment with business risk. In this scenario, the audit finding on excessive administrator privileges indicates a potentially high-impact control gap in critical financial systems, which may justify PAM if the expected reduction in loss exposure exceeds that of broader awareness training.
- C. Incorrect.
This is incorrect because implementation preference from IT operations is relevant to feasibility, but it should not drive the initial funding decision. Security budget recommendations at the executive level must be aligned to enterprise risk, financial impact, and strategic priorities rather than internal team preference.
- D. Incorrect.
This is incorrect because broad user reach does not automatically translate to higher financial value. While awareness training can be beneficial, the CISO should not assume that affecting more employees produces the best return. The organization already has evidence of a more concentrated but potentially more severe risk in privileged access over critical systems, which requires objective financial analysis rather than assumptions based on scope.