712-50 Question 415
Single answerAllocate financial resources to projects, processes and units within information security programA newly appointed CISO is preparing next year's information security budget after the company acquired two regional businesses. The board has directed all executives to limit budget growth to 3%, while internal audit has reported weak third-party risk management and inconsistent identity governance across the combined enterprise. Several business unit leaders are each requesting dedicated security tools for their own teams, arguing that their risks are unique. The CISO must allocate limited financial resources across projects, processes, and operating units while demonstrating business alignment and defensible prioritization. Which approach should the CISO take FIRST to make the most effective funding allocation decision?
- A
Allocate the largest share of the budget to the business units generating the highest revenue, because protecting revenue-producing units yields the greatest return
- B
Fund the projects that close the most severe enterprise risks and regulatory gaps first, using a risk-based prioritization model tied to business objectives and integration needs
- C
Distribute the budget evenly across business units to avoid conflict and ensure each unit has baseline security capability
- D
Approve the business units' requests for separate tools so each team can address its own risks without waiting for enterprise standardization
Show answer and explanation
Correct answer: B
Explanation
At the executive level, information security budgeting should be driven by enterprise risk, business priorities, compliance obligations, and control effectiveness rather than politics, equal distribution, or isolated business unit preferences. In this scenario, the CISO has clear signals about where limited resources should be concentrated: audit-identified weaknesses, post-merger integration gaps, and enterprise-wide control issues such as identity governance and third-party risk management. A risk-based funding model helps the CISO justify decisions to the board, demonstrate due care, and optimize limited resources across projects, processes, and units. This approach is consistent with widely accepted practices in security governance and enterprise risk management, including principles reflected in NIST CSF, ISO/IEC 27001 risk treatment planning, and governance guidance such as COBIT, all of which emphasize aligning security investments to prioritized business risk and organizational objectives.
- A. Incorrect.
This is incorrect because revenue contribution alone is not a sufficient basis for security funding decisions. High-revenue units may not represent the highest enterprise risk exposure, compliance obligation, or control deficiency. A CCISO is expected to allocate resources based on risk, business impact, legal and regulatory requirements, and strategic objectives rather than simple revenue weighting.
- B. Correct.
This is correct because a risk-based prioritization model is the most defensible and effective way to allocate constrained security funding. In this scenario, the organization faces post-acquisition integration issues, audit findings, and specific weaknesses in third-party risk management and identity governance. Funding should therefore be directed first toward initiatives that reduce the greatest enterprise risk, address control gaps, support business integration, and satisfy governance expectations. This aligns security spending with business objectives and provides a clear rationale to the board and business leaders.
- C. Incorrect.
This is incorrect because equal distribution is easy politically but weak from a governance and risk management perspective. Business units rarely have identical risk profiles, control maturity, regulatory obligations, or threat exposure. Even allocation can result in underfunding critical risks and overfunding lower-priority needs. This option reflects a common misconception that fairness in budgeting means equality rather than risk-informed appropriateness.
- D. Incorrect.
This is incorrect because approving separate tools for each business unit typically increases duplication, operating cost, integration complexity, and control inconsistency. In an acquisition context, enterprise standardization and rationalization usually improve economies of scale, visibility, and governance. While some unit-specific needs may exist, approving decentralized tools as the first step is not the best financial allocation strategy when budgets are constrained.