712-50 Question 413
Single answerAcquire and manage the necessary resources for implementation and management of information security planA newly appointed CISO is preparing the first-year implementation roadmap for an enterprise information security program approved by the board. The roadmap includes identity governance, security monitoring improvements, and third-party risk management. Funding is limited, several business units are competing for the same skilled staff, and the CFO has asked for a defensible resource plan before releasing budget. Which action should the CISO take FIRST to acquire and manage the necessary resources most effectively?
- A
Build a risk-prioritized resource plan that maps required people, technology, and external services to business objectives, regulatory obligations, and implementation milestones
- B
Request the full budget immediately based on industry security spending benchmarks and adjust staffing after tools are purchased
- C
Outsource most security functions to a managed service provider to avoid internal hiring delays and simplify accountability
- D
Acquire the monitoring platform first because visibility gaps create the greatest operational pressure, then determine the remaining resource needs during deployment
Show answer and explanation
Correct answer: A
Explanation
For CCISO-level decision making, acquiring and managing resources is not just a procurement exercise; it is a governance and strategy activity. The strongest first step is to translate the approved security strategy into a risk-prioritized operating plan showing required capabilities, staffing model, technology dependencies, timing, and budget. This aligns with widely accepted security management practices such as risk-based planning, capability maturity assessment, and business alignment found in frameworks and guidance including NIST CSF, NIST SP 800-53/800-137 concepts for control implementation and monitoring, ISO/IEC 27001 resource and competence expectations, and COBIT governance principles. A defensible plan typically includes: required roles and skills, internal versus external sourcing decisions, implementation sequencing, operational run costs, measurable outcomes, and dependencies with IT and business teams. This enables the CISO to justify resource requests to the CFO and board while managing scarce talent and ensuring the information security plan can be implemented sustainably.
- A. Correct.
Correct. The CISO should first develop a risk-based, business-aligned resource plan that identifies what capabilities are needed, when they are needed, and whether they should be fulfilled through internal staff, contractors, or third parties. This approach supports defensible budgeting, sequencing, and governance. It also allows the CISO to justify tradeoffs based on business impact, regulatory commitments, and program milestones rather than intuition or vendor pressure.
- B. Incorrect.
Incorrect. Industry benchmarks can provide context, but they are not sufficient as the primary basis for acquiring resources. Benchmark-driven budgeting without a capability and dependency analysis often leads to misallocation, such as buying tools before ensuring the organization has the staff, processes, and integration capacity to operate them effectively.
- C. Incorrect.
Incorrect. Managed services may be part of the solution, especially where specialized skills are scarce, but outsourcing should follow a sourcing analysis, not replace it. The CISO must first determine which capabilities are strategic, which can be externalized, what oversight is required, and whether vendor risk, contract terms, and service levels align with the security plan.
- D. Incorrect.
Incorrect. Buying a high-priority tool first may feel responsive, but it is not the best first step in enterprise resource management. Tool acquisition before understanding staffing, process maturity, integration requirements, and downstream operating costs can create shelfware, delayed implementation, or weak control outcomes.