712-50 Question 414
Single answerAllocate financial resources to projects, processes and units within information security programA newly appointed CISO is finalizing next year's information security budget after the board required a 12% reduction in discretionary spending. The organization operates in three regions and recently identified: (1) a high likelihood of ransomware disrupting manufacturing operations, (2) repeated audit findings on privileged access reviews, and (3) low adoption of a proposed threat intelligence platform requested by the security operations team. The CFO has asked the CISO to justify how limited funds will be allocated across security projects, operational processes, and regional units. Which approach is the MOST appropriate for allocating the reduced budget?
- A
Allocate funds evenly across all security functions and regional units to preserve fairness and avoid internal conflict
- B
Prioritize funding based on quantified business risk, regulatory and audit obligations, and expected risk reduction, while deferring lower-value initiatives with unclear outcomes
- C
Shift most of the budget to the security operations center because ransomware is the most visible threat to executive leadership
- D
Allocate funds according to each regional unit's prior-year spending levels to maintain budget stability and simplify financial planning
Show answer and explanation
Correct answer: B
Explanation
The best answer is the risk-based allocation approach because the CISO's role includes directing investment to the areas that most effectively protect business objectives while meeting mandatory obligations. In practice, this means considering likelihood and impact of key risks, regulatory or audit-driven remediation needs, cost-benefit of proposed initiatives, and the expected reduction in residual risk. In the scenario, ransomware resilience and privileged access review deficiencies both have strong business justification, while a proposed platform with low expected adoption should face stronger scrutiny or be deferred. This aligns with broadly accepted security governance and risk management practices reflected in frameworks such as NIST CSF 2.0, NIST SP 800-30 for risk assessment, ISO/IEC 27001 and 27005 for risk-based information security management, and ISACA/COBIT principles emphasizing value delivery, risk optimization, and resource optimization. A mature CISO does not allocate budget by equal share, historical precedent, or executive visibility alone; instead, the CISO ties spending decisions to measurable business risk reduction and organizational priorities.
- A. Incorrect.
This is incorrect because equal distribution is administratively simple but not strategically sound. Information security resources should be allocated according to enterprise risk, compliance requirements, and business impact rather than perceived fairness. An even split can underfund critical remediation areas such as privileged access control deficiencies or high-impact ransomware resilience.
- B. Correct.
This is correct because a CISO should allocate scarce financial resources using a risk-based and business-aligned method. In this scenario, that means funding initiatives that address the most significant operational risk, satisfy audit and regulatory expectations, and demonstrate measurable reduction of exposure. It also means challenging projects with weak business cases, such as a tool with low anticipated adoption or unclear value realization.
- C. Incorrect.
This is incorrect because it overconcentrates spending on a single function based on executive visibility rather than balanced enterprise risk treatment. Although ransomware is a serious threat, the scenario also includes unresolved privileged access audit findings, which may increase both breach likelihood and compliance exposure. Budget allocation should reflect total organizational risk and control obligations, not just the most prominent threat narrative.
- D. Incorrect.
This is incorrect because prior-year spending is not a sufficient basis for current-year resource allocation. It assumes historical distributions still match present risk conditions and business priorities. In dynamic environments, relying on legacy spending patterns can perpetuate ineffective investments and fail to address newly identified control gaps or changing threat conditions.