712-50 Question 420
Single answerBalance the IT security investment portfolio based on EISA considerations and enterprise security prioritiesA newly appointed CISO is reviewing the enterprise security investment portfolio during annual planning. The board has approved only a modest budget increase and has directed the CISO to prioritize investments that best support revenue growth in the company’s expanding digital channel while also satisfying regulatory obligations in two highly regulated business units. Current proposals include: (1) expanding cloud workload protection for customer-facing applications, (2) replacing endpoint tools in low-risk back-office functions primarily because they are nearing end of life, (3) implementing stronger identity governance and privileged access controls across critical systems, (4) increasing security awareness training frequency for all staff, and (5) funding a new threat intelligence platform with limited integration to existing operations. Using EISA-style investment balancing and enterprise security priorities, which option is the BEST recommendation?
- A
Prioritize identity governance and privileged access controls first, then cloud workload protection for revenue-generating digital services, while deferring low-risk endpoint refresh and the standalone threat intelligence platform unless a quantified risk reduction or business dependency is demonstrated.
- B
Allocate the largest share of the budget to replacing endpoint tools across all departments because unsupported technology creates broad exposure, then distribute remaining funds evenly across the other initiatives to maintain fairness.
- C
Fund the new threat intelligence platform and increase awareness training first because these improve enterprise-wide visibility and culture, then postpone investments tied to specific business units until the next budget cycle.
- D
Invest primarily in the expanding digital channel’s cloud workload protection and defer identity governance because access management projects often take longer to realize value than tactical technical controls.
Show answer and explanation
Correct answer: A
Explanation
The best answer is the one that balances investments according to enterprise priorities, risk reduction, compliance needs, and business enablement rather than technology lifecycle or equal distribution. In a CCISO context, balancing the security investment portfolio means treating security spending as a portfolio of strategic, operational, compliance, and resilience investments. The CISO should prioritize initiatives that protect critical business objectives, reduce high-impact enterprise risk, and support legal or regulatory obligations. In this scenario, identity governance and privileged access controls address systemic risk and are commonly emphasized in governance frameworks and audit expectations. Cloud workload protection for customer-facing services aligns with business growth and protection of strategic revenue streams. By contrast, replacing endpoint tools in low-risk areas may be valid later but is not the highest priority absent demonstrated material risk. Likewise, a threat intelligence platform without strong integration may offer limited return on investment. This approach is consistent with established practices in risk-based security management reflected in frameworks and guidance such as NIST CSF 2.0 (especially Govern and Identify functions), NIST SP 800-53 principles for access control and risk management, ISO/IEC 27001 risk treatment concepts, and general governance expectations that security investment decisions should be linked to business objectives, risk appetite, and measurable outcomes.
- A. Correct.
Correct. This recommendation best aligns security spending to enterprise priorities and EISA-style portfolio balancing by directing investment toward controls that protect critical business processes, regulated environments, and high-consequence access paths. Identity governance and privileged access management typically reduce systemic risk across multiple assets and are highly relevant to both regulatory expectations and breach prevention. Cloud workload protection for customer-facing digital services supports the board’s revenue-growth objective while protecting a strategic business initiative. Deferring the low-risk endpoint refresh is appropriate when risk is lower and compensating controls may exist. Deferring a threat intelligence platform with limited operational integration is also sound because security investments should be tied to measurable risk reduction, operational effectiveness, and business value rather than tool acquisition alone.
- B. Incorrect.
Incorrect. Although end-of-life technology can increase risk, replacing endpoint tools across all departments simply because they are nearing end of life does not reflect a risk-based or business-aligned portfolio strategy. An even distribution of residual funds is also not how senior security leaders should allocate capital; investments should be prioritized by business impact, regulatory necessity, threat exposure, and expected reduction of enterprise risk. This option reflects a common misconception that fairness across departments is preferable to risk-based prioritization.
- C. Incorrect.
Incorrect. Threat intelligence and awareness training can be valuable, but funding them first in this scenario does not best support the stated enterprise priorities. The threat intelligence platform has limited integration, which reduces its immediate operational value, and awareness training frequency increases may produce incremental benefit but are unlikely to address the most material risks compared with identity governance, privileged access, and protection of revenue-generating digital services. Postponing investments tied to regulated units would also be weak governance because compliance obligations and critical-risk treatment usually carry higher urgency.
- D. Incorrect.
Incorrect. Protecting the expanding digital channel is important, but deferring identity governance is not the best portfolio decision. Identity governance and privileged access controls often provide broad risk reduction across the enterprise, especially for critical systems and regulated environments, and they address one of the most common root causes of significant security incidents: excessive or poorly governed access. While such programs can take time, their strategic value and regulatory relevance often justify prioritization over narrower tactical controls alone.