712-50 exam dumps

712-50 practice question 43 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 43

Single answerImplement and manage information security strategies, plans, policies, and procedures to reduce regulatory risk

A multinational healthcare technology company operates in the EU and several U.S. states. Following an internal audit, the board learns that customer personal data is stored in multiple business platforms with inconsistent retention periods, unclear ownership, and conflicting breach notification procedures. Regulators have recently increased scrutiny, and the CEO asks the CISO to reduce regulatory risk without unnecessarily slowing product delivery. Which action should the CISO prioritize FIRST to create a sustainable security governance approach?

  1. A

    Deploy additional data loss prevention (DLP) tools across all business units to identify regulated data and block unauthorized transfers

  2. B

    Establish an enterprise-wide information governance program that maps regulatory obligations to data classes, assigns control ownership, and standardizes policies for retention, handling, and incident response

  3. C

    Instruct legal counsel to manage all compliance decisions centrally and require business units to request case-by-case exceptions for data handling activities

  4. D

    Launch mandatory security awareness training focused on privacy regulations and breach reporting obligations for all employees

Show answer and explanation

Correct answer: B

Explanation

A CCISO-level leader should first address structural governance weaknesses when regulatory risk stems from inconsistent practices, unclear ownership, and conflicting procedures. The most effective initial action is to establish an enterprise-wide information governance program that translates legal and regulatory requirements into actionable policies, standards, and procedures. This should include data classification, records retention requirements, breach notification decision criteria, control ownership, exception handling, and oversight mechanisms. Once governance is defined, the organization can implement supporting controls such as DLP, monitoring, workflow automation, and workforce training in a coordinated way. This approach aligns with widely recognized practices in ISO/IEC 27001 and 27002 for policy governance and control ownership, NIST Cybersecurity Framework governance principles, and privacy/accountability expectations reflected in regulations such as the GDPR, which emphasize organizational measures, defined responsibilities, and demonstrable compliance.

  • A. Incorrect.

    This is a plausible response because DLP can help detect and restrict movement of sensitive data, but it is not the best first step. The scenario highlights inconsistent retention, unclear ownership, and conflicting procedures, which are governance and policy problems before they are tooling problems. Deploying technology without first defining data classes, accountability, and regulatory requirements often leads to fragmented controls and limited risk reduction.

  • B. Correct.

    This is the best answer. The root issue is the absence of a coherent governance framework connecting legal obligations to business processes, data classification, ownership, and standardized procedures. A CISO seeking to reduce regulatory risk sustainably should first create an enterprise-wide program that aligns security strategy, policies, and procedures with applicable regulations. This enables consistent retention schedules, documented accountability, harmonized incident response and breach notification requirements, and risk-based implementation that supports the business rather than relying on ad hoc decisions.

  • C. Incorrect.

    This is incorrect because it over-centralizes operational compliance in legal and does not establish shared accountability with data owners, privacy, security, and business leadership. Legal interpretation is important, but regulatory risk reduction requires governance mechanisms, control ownership, and operationalized policies embedded in business processes. A case-by-case exception model also tends to slow delivery and create inconsistency rather than scalable compliance.

  • D. Incorrect.

    Training is useful and should be part of the broader program, but it is not the first priority in this situation. Employees cannot be trained effectively on retention, handling, and notification obligations if those requirements are currently inconsistent or undefined across systems and business units. Training addresses awareness, not the underlying governance gaps causing regulatory exposure.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam