712-50 exam dumps

712-50 practice question 42 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 42

Single answerBe familiar with international security and risk standards such as ISO 27000, and 31000 series

A multinational manufacturer is integrating two recently acquired business units. The board has asked the CISO to present a single, enterprise-wide approach that aligns cyber risk decisions with overall business risk while also supporting eventual certification of the security program. One acquired unit currently uses a control-heavy security framework, while the other uses an informal risk register with inconsistent criteria. The CISO wants to avoid treating information security risk in isolation from enterprise risk management. Which approach is the MOST appropriate first step?

  1. A

    Adopt ISO/IEC 27001 controls immediately across all business units and defer enterprise risk alignment until after the certification scope is defined

  2. B

    Use ISO 31000 to establish a common enterprise risk management framework and risk criteria, then apply ISO/IEC 27005 and ISO/IEC 27001 within that context for information security risk treatment and control selection

  3. C

    Standardize on ISO/IEC 27002 as the enterprise risk framework because it provides implementation guidance for both business risk and information security risk

  4. D

    Replace existing risk registers with a new vulnerability scoring model and use that as the basis for board-level risk reporting

Show answer and explanation

Correct answer: B

Explanation

The key issue in this scenario is integration: the board wants cyber risk decisions aligned with overall business risk, and the CISO also wants to support eventual security certification. ISO 31000 is the appropriate starting point because it establishes risk management principles and a framework that can be embedded into governance and enterprise decision-making. Once common risk criteria and governance are defined, ISO/IEC 27005 can be used to perform information security risk management in a way that is consistent with enterprise risk practices. ISO/IEC 27001 then provides the certifiable ISMS requirements, including risk-based selection of controls, with ISO/IEC 27002 serving as guidance for those controls. This reflects widely accepted practice: use ISO 31000 for organization-wide risk governance, and the ISO/IEC 27000 family for information security management and controls. Relevant references include ISO 31000: Risk management - Guidelines; ISO/IEC 27001: Information security, cybersecurity and privacy protection - Information security management systems - Requirements; ISO/IEC 27005: Guidance on managing information security risks; and ISO/IEC 27002: Information security controls guidance.

  • A. Incorrect.

    This is not the best first step. ISO/IEC 27001 is the standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), and it supports certification. However, immediately imposing controls before aligning risk governance and criteria across the enterprise can create inconsistency with broader enterprise risk management. The scenario specifically states that the CISO wants to avoid treating information security risk in isolation. Starting with controls before establishing common risk context may result in misaligned priorities and weak board-level integration.

  • B. Correct.

    This is the best answer. ISO 31000 provides principles and guidelines for enterprise risk management and is designed to integrate risk management into organizational governance, strategy, and decision-making. Using ISO 31000 first helps the organization define common risk criteria, appetite, ownership, and reporting across the merged entities. Within that enterprise context, ISO/IEC 27005 can then be used to manage information security risk specifically, and ISO/IEC 27001 can be used to implement and certify the ISMS with risk treatment and control selection aligned to business objectives. This sequence supports both board-level integration and eventual certification.

  • C. Incorrect.

    This is incorrect because ISO/IEC 27002 is not an enterprise risk management framework. It provides guidance on information security controls that can support the implementation of controls selected through the ISO/IEC 27001 risk treatment process. It does not replace an enterprise risk framework such as ISO 31000, nor does it address broader business risk governance in the way the scenario requires. A candidate might choose this option because ISO/IEC 27002 is control-oriented and widely used, but it is too narrow for the stated objective.

  • D. Incorrect.

    This is incorrect because vulnerability scoring is only one input into risk analysis and is not sufficient for enterprise risk management or board reporting. Vulnerability severity does not account for business context, likelihood in a specific environment, treatment decisions, risk appetite, or non-technical risks. The board asked for a unified approach aligning cyber risk with overall business risk, which requires governance, risk criteria, and consistent evaluation methods rather than a purely technical scoring model.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam