712-50 Question 421
Single answerBalance the IT security investment portfolio based on EISA considerations and enterprise security prioritiesA newly appointed CISO is reviewing next year's security budget after the board approved an aggressive digital expansion strategy. The enterprise plans to launch new customer-facing APIs, migrate several business services to the cloud, and expand into a region with stricter privacy requirements. However, the current security portfolio is heavily weighted toward renewing legacy perimeter tools because those investments were historically easy to justify. The CEO asks the CISO to rebalance security spending using EISA considerations while aligning with enterprise priorities. Which action should the CISO take FIRST to create the most defensible investment portfolio?
- A
Map proposed and existing security investments to business objectives, regulatory obligations, and risk scenarios, then prioritize funding based on enterprise impact and expected risk reduction
- B
Preserve the current portfolio allocation because existing controls are already deployed and replacing them would create unnecessary operational disruption
- C
Shift most of the budget to the newest cloud-native security tools because the enterprise is migrating services and modern platforms are strategically important
- D
Allocate the largest share of the budget to audit and compliance reporting capabilities because expansion into a stricter privacy jurisdiction creates the highest visibility risk
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because executive-level security portfolio management is fundamentally about aligning investments with enterprise strategy and prioritizing initiatives that produce the greatest business-relevant risk reduction. In a scenario involving digital expansion, cloud migration, customer-facing APIs, and new privacy obligations, a CISO should first reassess the portfolio against changing business drivers and threat scenarios. This is consistent with widely accepted best practices from NIST CSF, ISO/IEC 27001 risk treatment principles, and FAIR-style risk-informed decision making: identify business context, assess risks, evaluate control effectiveness, and prioritize treatment based on impact, likelihood, and strategic importance. In CCISO practice, the CISO should also consider whether proposed investments are implementable within the enterprise architecture, integrated with existing operations, sustainable over time, and appropriate for current and emerging risks. The key mistake in the other options is overemphasizing history, technology fashion, or compliance optics instead of taking a balanced, enterprise-prioritized, risk-based investment approach.
- A. Correct.
Correct. A CISO balancing the security investment portfolio should begin by linking investments to enterprise strategy, material risks, and compliance drivers rather than simply continuing historical spending patterns or following technology trends. In CCISO terms, this reflects a risk-based, business-aligned approach to security investment governance. Using EISA considerations in practice means evaluating whether investments are effective and aligned to the enterprise mission, whether they support implementation and integration needs, whether they are sustainable and appropriate for the operating environment, and whether they produce measurable value in reducing risk or enabling business objectives.
- B. Incorrect.
Incorrect. Preserving the current allocation reflects budget inertia rather than portfolio management. Legacy perimeter investments may still have value, but retaining them without reassessment ignores changes in the threat landscape, cloud adoption, API exposure, and privacy obligations. A mature CISO must periodically rebalance the portfolio as business priorities and risk exposure change.
- C. Incorrect.
Incorrect. This option is plausible because cloud migration often requires new controls, but shifting most of the budget to cloud-native tools without a broader analysis is a technology-led rather than risk-led decision. It may underfund critical areas such as identity, data protection, third-party risk, API security, resilience, or privacy governance. Portfolio balance requires examining the full enterprise risk picture, not overcorrecting toward a single domain.
- D. Incorrect.
Incorrect. Compliance capabilities are important, especially when entering stricter jurisdictions, but prioritizing audit/reporting above all else can produce a check-box program that satisfies visibility needs without materially reducing operational or strategic risk. Effective investment decisions should address regulatory requirements as one factor among several, including business enablement, threat exposure, control effectiveness, and resilience.