712-50 exam dumps

712-50 practice question 5 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 5

Single answer

A newly appointed CISO at a global manufacturing company has been asked by the board to strengthen the organization's information security governance program after several audit findings showed inconsistent risk ownership, duplicate security initiatives across business units, and weak reporting of security performance to executive leadership. The company already has technical security controls in place, but accountability and decision-making remain unclear. Which action should the CISO take FIRST to establish an effective governance foundation?

  1. A

    Implement a new security toolset to standardize technical controls across all business units

  2. B

    Define a governance structure with clear roles, decision rights, reporting lines, and executive oversight aligned to business objectives

  3. C

    Outsource policy management to an external consulting firm to accelerate compliance with industry standards

  4. D

    Require each business unit to independently create its own security metrics and remediation plans

Show answer and explanation

Correct answer: B

Explanation

The best first step is to establish a formal information security governance structure aligned to enterprise strategy. In this scenario, the main issues are unclear accountability, fragmented ownership, and poor executive reporting. Those are governance deficiencies, not merely operational or technical shortcomings. An effective governance program includes leadership commitment, defined organizational structures, documented roles and responsibilities, decision-making authority, risk ownership, escalation paths, and performance reporting to senior management and the board. This approach is consistent with widely accepted practices in frameworks such as COBIT, which emphasizes governance objectives, accountability, and alignment with enterprise goals; ISO/IEC 27014, which focuses specifically on governance of information security; and ISO/IEC 27001, which requires leadership, roles, responsibilities, and performance evaluation. Once governance is defined, the CISO can more effectively standardize metrics, harmonize initiatives, prioritize investments, and implement or optimize technical controls under clear executive oversight.

  • A. Incorrect.

    This is incorrect because the scenario identifies governance failures, not primarily a technology gap. Standardizing tools may improve control consistency later, but without defined accountability, leadership oversight, and decision authority, the same governance problems will persist. A common misconception is that inconsistent outcomes are best solved first with technology, when in fact governance should define how security decisions are made and who is responsible before tools are selected or expanded.

  • B. Correct.

    This is correct because the root issue is the absence of an effective information security governance framework. A governance structure should establish leadership accountability, organizational roles, risk ownership, escalation paths, decision rights, and reporting mechanisms tied to enterprise objectives. This creates the foundation for managing policies, metrics, investments, and risk decisions consistently across business units. In a CCISO context, governance must align security with business strategy and provide executive and board visibility.

  • C. Incorrect.

    This is incorrect because external support may help draft policies or benchmark the program, but governance accountability cannot be delegated away from leadership. The organization still needs internal ownership, authority, and oversight. Choosing this option reflects the misconception that compliance documentation alone creates governance maturity. Effective governance requires internal structures and processes, not just externally produced artifacts.

  • D. Incorrect.

    This is incorrect because allowing each business unit to define its own metrics and remediation plans independently would likely reinforce the inconsistency already identified by audit. Governance should provide enterprise-wide standards for reporting, accountability, and prioritization, while still allowing localized execution where appropriate. This option appeals to decentralization, but it does not solve the core problem of fragmented decision-making.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam