712-50 Question 416
Single answerA global manufacturing company is midway through a 3-year digital transformation program focused on cloud adoption, plant connectivity, and expansion into new markets. The board approved funding for a security analytics platform 18 months ago based on a business case that projected reduced incident response time, lower downtime in factories, and improved audit readiness. The CISO now learns that operating costs for the platform are 35% higher than forecast because of increased data ingestion and specialized staffing, while business units are planning additional connected devices that will further increase costs. The CEO asks whether the program should be expanded, reduced, or restructured. Which action should the CISO take FIRST to properly oversee cost management and ROI while ensuring alignment with the strategic plan?
- A
Recalculate the business case using updated total cost of ownership, quantified business outcomes, and strategic objectives, then present options such as scope optimization, phased expansion, or alternate operating models
- B
Approve the requested expansion because the original board approval demonstrates sufficient strategic alignment and security spending should not be delayed
- C
Reduce the platform's data retention and monitoring coverage immediately to bring spending back within the original budget, then revisit business value after year-end
- D
Compare the platform's cost only against peer organizations' security spending percentages and continue funding if the company remains near industry average
Show answer and explanation
Correct answer: A
Explanation
The best first step is to refresh the investment analysis and governance view of the project. In senior security leadership, ROI for security initiatives is rarely measured as direct revenue generation alone; it is more often evaluated through reduced loss exposure, operational resilience, improved process efficiency, reduced downtime, audit and compliance efficiency, and support for strategic business initiatives. Because the original assumptions have changed, the CISO should revisit the business case using updated TCO, expected benefits, capacity demands, and strategic drivers. This enables informed decisions such as right-sizing telemetry, renegotiating contracts, changing deployment scope, adopting a phased expansion model, or selecting a different operating model.
This approach aligns with established governance and value-delivery principles found in frameworks such as COBIT, which emphasizes benefits realization, resource optimization, and alignment with enterprise objectives. It is also consistent with NIST CSF governance outcomes and general enterprise portfolio management practices, where major initiatives should be periodically reviewed for performance, cost, and alignment. The key leadership principle is that security spending should be governed as a business investment: measured, revalidated, and adjusted based on current evidence and strategic priorities.
- A. Correct.
This is the correct answer because the CISO's first responsibility is to reassess the initiative using current financial and operational data rather than relying on the original assumptions. A sound executive decision requires updated total cost of ownership (including licensing, staffing, integration, and scaling costs), measurable benefit realization, and evaluation against the enterprise strategic plan. Presenting decision options such as scope optimization, phased rollout, or alternative operating models allows leadership to choose a path based on value, risk reduction, and business priorities rather than on sunk costs or budget pressure alone.
- B. Incorrect.
This is incorrect because prior approval does not remove the need for ongoing governance, benefit realization review, and cost oversight. Conditions have materially changed, including higher operating costs and expanded demand. Continuing expansion without reassessment reflects a sunk-cost fallacy and weak portfolio governance. Strategic alignment must be continuously validated as business conditions, threat exposure, and cost structures evolve.
- C. Incorrect.
This is incorrect because cutting retention and coverage immediately may reduce cost, but doing so before reassessing business requirements, compliance needs, operational dependencies, and expected outcomes can damage risk visibility and undermine the program's intended benefits. A CCISO should make cost-control decisions through governance and analysis, not through ad hoc reductions that may create larger business and security gaps.
- D. Incorrect.
This is incorrect because industry-average spending is only a rough benchmark and does not establish ROI or strategic fit. Two organizations with similar spending ratios can have very different risk profiles, regulatory obligations, operating models, and transformation goals. Cost management for security projects should be based on business outcomes, risk treatment value, and enterprise strategy, not only on external spending comparisons.