712-50 Question 412
Single answerAcquire and manage the necessary resources for implementation and management of information security planA newly appointed CISO is preparing the first-year rollout of an enterprise information security plan for a rapidly growing company that has expanded into three new regions through acquisition. The board has approved the strategy, but the budget cycle is tight and several business unit leaders are competing for the same skilled staff and technology funds. The security program requires new monitoring capabilities, integration work across acquired environments, and additional governance support. To maximize the likelihood of successful implementation, which action should the CISO take FIRST when acquiring and managing the necessary resources?
- A
Build a risk-based resource plan that maps required people, skills, technologies, and funding to prioritized business objectives, regulatory obligations, and implementation milestones
- B
Request immediate headcount increases for the security team based on industry staffing ratios and defer technology planning until the next budget cycle
- C
Purchase the monitoring platform with the broadest feature set available and require business units to adapt their processes around the tool
- D
Outsource most security functions to a managed service provider to avoid internal competition for resources and simplify governance
Show answer and explanation
Correct answer: A
Explanation
The best first action is to develop a risk-based resource plan aligned to the approved information security strategy. In CCISO practice, acquiring and managing resources is not simply a budgeting exercise; it requires translating strategic objectives into specific capability needs across people, process, and technology. A strong resource plan identifies critical initiatives, dependencies, required competencies, sourcing options, timelines, and measurable outcomes. It also helps the CISO justify investment decisions to executive leadership by linking them to risk reduction, legal and regulatory obligations, resilience goals, and business enablement. This approach is consistent with widely accepted governance and risk management practices reflected in frameworks such as NIST Cybersecurity Framework, NIST SP 800-53's emphasis on resourcing and control implementation planning, ISO/IEC 27001's requirement to determine and provide resources for the information security management system, and COBIT's focus on aligning resources with enterprise objectives. In short, the CISO should first determine what resources are needed based on risk and business priorities, then decide whether to obtain them through hiring, reallocation, tooling, or third-party services.
- A. Correct.
Correct. The CISO should first create a risk-based resource plan tied to business priorities, compliance requirements, and the implementation roadmap. This establishes what resources are actually needed, when they are needed, and why they are justified. It also supports defensible trade-off decisions in a constrained budget environment and helps align staffing, tooling, and third-party support with the enterprise security strategy.
- B. Incorrect.
Incorrect. Industry ratios can provide context, but they are not a sound primary basis for resource acquisition. They ignore the organization's specific risk profile, integration complexity, regulatory exposure, and maturity level. Deferring technology planning also weakens implementation sequencing and may create dependencies that the program cannot meet later.
- C. Incorrect.
Incorrect. Buying a feature-rich platform before confirming business requirements, integration feasibility, staffing capacity, and operational processes is a common mistake. Tool-first decisions often lead to shelfware, poor adoption, cost overruns, and control gaps. Resource acquisition should follow prioritized requirements, not vendor capability breadth alone.
- D. Incorrect.
Incorrect. Managed services may be appropriate for selected capabilities, but outsourcing most functions as a first step is not inherently the best resource strategy. It can introduce vendor concentration risk, unclear accountability, integration challenges, and governance overhead. The CISO should determine sourcing choices only after identifying required capabilities and evaluating make-versus-buy options against risk, cost, and control needs.