712-50 Question 410
Single answerAnalyze, forecast and develop the operational budget of the security departmentA newly appointed CISO is preparing next year's operational budget for the security department after the company completed two acquisitions and expanded into a regulated market. Finance has asked for a defensible budget forecast tied to business growth, while the CEO has stated that large capital purchases are unlikely to be approved this year. The security team currently has rising incident response costs, overlapping tool subscriptions from acquired entities, and increased audit requirements. Which approach should the CISO take FIRST to develop the most credible operational budget proposal?
- A
Start with last year's approved budget and apply a uniform percentage increase to all security cost centers to account for business expansion
- B
Build a risk-based operational budget forecast by mapping new business activities and regulatory obligations to required security services, then baseline run-rate costs and identify consolidation opportunities in duplicated subscriptions
- C
Request immediate replacement of legacy security platforms across all acquired companies so the budget reflects the ideal target-state architecture
- D
Defer the budget submission until the acquisitions are fully integrated, because current cost estimates will be too uncertain to justify to finance
Show answer and explanation
Correct answer: B
Explanation
For a CCISO-level leader, operational budgeting should be business-aligned, risk-informed, and evidence-based. In practice, this means translating strategic changes such as acquisitions, geographic expansion, and new regulatory exposure into ongoing security service demand and related operating expenses. Operational budgets typically include personnel, MSSP or consulting costs, licensing and subscriptions, audit support, training, travel, incident response retainers, and maintenance. A mature approach begins with understanding business drivers and compliance obligations, baselining existing run-rate costs, forecasting demand changes, and identifying cost efficiencies such as eliminating redundant tools from acquired entities. This aligns with widely accepted security governance and budgeting practices reflected in frameworks such as NIST CSF 2.0 Govern and Identify functions, COBIT governance principles, and ISO/IEC 27001 management system planning concepts, all of which emphasize aligning security resources with organizational objectives, risk, and compliance requirements. The best answer is the one that creates a defensible, finance-ready operational budget rather than relying on simplistic inflationary increases, idealized transformation spending, or delay.
- A. Incorrect.
This is a common but weak budgeting approach. Using last year's budget as the primary baseline may be acceptable for minor adjustments, but it is not sufficient when the organization has materially changed through acquisitions and market expansion. A flat percentage increase ignores changes in threat exposure, compliance scope, duplicated services, and operational demand. It also does not provide the defensible business rationale finance and executive leadership expect from a CISO.
- B. Correct.
This is correct. A credible operational budget should be risk-based, aligned to business strategy, and grounded in forecasted operating requirements. In this scenario, the CISO should first assess how the acquisitions and entry into a regulated market affect ongoing security services such as monitoring, incident response, IAM administration, vulnerability management, third-party oversight, and compliance support. The CISO should then establish current run-rate costs, including personnel, managed services, subscriptions, training, and audit support, while also identifying quick savings from overlapping tools introduced by the acquisitions. This approach produces a defensible budget tied to business growth, regulatory requirements, and cost optimization rather than aspirational spending.
- C. Incorrect.
This is incorrect because it prioritizes ideal-state transformation over immediate operational budgeting constraints. The scenario explicitly states that large capital purchases are unlikely to be approved. While platform rationalization may be a valid long-term strategy, immediately budgeting for broad technology replacement is unlikely to be approved and does not address the need for a realistic operational forecast. It also risks overstating near-term costs before completing a proper needs and overlap analysis.
- D. Incorrect.
This is incorrect because budget development cannot be paused until uncertainty disappears. Senior security leaders are expected to forecast under changing conditions using reasonable assumptions, ranges, and documented dependencies. Deferring submission would undermine governance and planning. A better practice is to submit a justified operational budget based on current business requirements, known regulatory obligations, and integration assumptions, then revisit forecasts through normal budget review cycles.