712-50 Question 49
Single answerA newly appointed CISO is consolidating the enterprise compliance program after a merger. The organization must maintain PCI DSS compliance for its payment environment, support annual SOC 2 examinations requested by customers, and prepare for an external ISO/IEC 27001 certification audit. Internal audit has reported duplicated testing, inconsistent control wording across frameworks, and control owners who treat audits as one-time events rather than ongoing obligations. The CEO asks the CISO for the MOST effective next step to improve efficiency and audit readiness without weakening assurance. What should the CISO do FIRST?
- A
Create a unified control framework that maps common control objectives to PCI DSS, SOC 2 criteria, and ISO/IEC 27001 requirements, then assign owners and evidence requirements for continuous monitoring
- B
Schedule all external audits earlier in the year so deficiencies can be remediated before year-end and ask each auditor to provide its own preferred control set
- C
Adopt ISO/IEC 27001 certification as the master standard and discontinue separate PCI DSS and SOC 2 control testing because ISO certification demonstrates broad security compliance
- D
Outsource all compliance activities to a consulting firm so business units no longer need to maintain control evidence or participate in audit preparation
Show answer and explanation
Correct answer: A
Explanation
The best answer is to establish an integrated compliance control framework with mapped control objectives, ownership, and evidence requirements. This is a common best practice in enterprise compliance management because multiple regimes often test similar themes such as access control, logging, change management, risk assessment, and incident response. A rationalized control library reduces duplicated work and supports consistent testing across compliance audits and certification activities.
From a governance perspective, the CISO should treat compliance as an ongoing program rather than a series of isolated audit events. That means defining common controls, mapping them to applicable obligations, assigning accountable owners, documenting procedures, and implementing periodic evidence collection and monitoring. This aligns with the intent of ISO/IEC 27001's management system approach, where controls operate within a continual improvement cycle, and with SOC 2's emphasis on the design and operating effectiveness of controls over time. It also supports PCI DSS, which contains explicit technical and procedural requirements that must be maintained continuously in scope environments rather than addressed only before assessment.
Relevant references and best practices include: ISO/IEC 27001 requirements for establishing, implementing, maintaining, and continually improving an information security management system; PCI DSS guidance on maintaining security controls continuously for cardholder data environments; and AICPA SOC 2 reporting principles requiring management-defined controls that can be tested for design and operating effectiveness. In a CCISO context, the strategic objective is not merely passing audits, but building a sustainable enterprise compliance program with clear control ownership, harmonized requirements, and defensible assurance.
- A. Correct.
Correct. A unified control framework is the most effective first step because it addresses the root causes described in the scenario: duplicated testing, inconsistent control language, and weak ownership. Mapping common controls across PCI DSS, SOC 2, and ISO/IEC 27001 allows the organization to rationalize overlapping requirements, define a single source of truth for control statements, assign accountable owners, and standardize evidence collection. Adding continuous monitoring expectations shifts the organization away from a point-in-time audit mindset toward an ongoing compliance process, which is consistent with mature governance and assurance practices.
- B. Incorrect.
Incorrect. Moving audit dates earlier may help with remediation timing, but it does not solve the underlying operational problem of fragmented controls and duplicated testing. Asking each auditor to provide its own preferred control set would likely increase inconsistency rather than reduce it. Audit scheduling is a tactical adjustment, whereas the scenario calls for a strategic compliance program improvement.
- C. Incorrect.
Incorrect. ISO/IEC 27001 certification does not replace PCI DSS obligations for payment card environments, nor does it eliminate the need for SOC 2 reporting when customers require independent attestation against Trust Services Criteria. This option reflects the common misconception that one certification can automatically satisfy all regulatory, contractual, and attestation needs. In practice, frameworks overlap but are not interchangeable.
- D. Incorrect.
Incorrect. External specialists can support compliance activities, but management retains responsibility for internal controls, evidence quality, and audit readiness. Removing business-unit ownership would weaken the control environment and reduce accountability. Auditors and certification bodies expect controls to be embedded in operations, not treated solely as outsourced administrative tasks.