712-50 exam dumps

712-50 practice question 50 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 50

Single answerUnderstand the information security compliance process and procedures

A newly appointed CISO at a multinational healthcare company discovers that separate business units have been responding independently to regulatory obligations such as HIPAA, GDPR, PCI DSS, and local privacy laws. During a recent internal review, the audit committee found duplicated controls in some areas, control gaps in others, and inconsistent evidence collection for audits. The board has asked the CISO to establish a more effective information security compliance process that reduces redundancy while improving accountability and audit readiness. Which action should the CISO take FIRST to build a sustainable compliance program?

  1. A

    Create a unified compliance framework that maps legal, regulatory, and contractual requirements to common security controls, control owners, and evidence requirements

  2. B

    Purchase a governance, risk, and compliance (GRC) platform to automate policy exception management and audit reporting across all business units

  3. C

    Schedule independent external audits for each major regulation to identify all missing controls before redesigning the compliance program

  4. D

    Require each business unit leader to certify quarterly that their teams are compliant with all applicable regulations and standards

Show answer and explanation

Correct answer: A

Explanation

An effective information security compliance process begins with understanding applicable obligations, translating them into a normalized control framework, assigning accountable owners, and defining how compliance evidence will be collected and maintained. In a multinational environment with overlapping obligations, the most efficient approach is to map multiple regulations and contractual requirements to a common set of controls rather than treating each mandate separately. This aligns with widely accepted practices in governance and compliance management, including the use of integrated control frameworks and control mapping approaches seen in standards and guidance such as ISO/IEC 27001, NIST SP 800-53, and common audit-readiness practices. Once the framework, ownership model, and evidence procedures are established, the organization can then enable the process with GRC tooling, internal assessments, management attestations, and external audits. The key leadership decision is to fix the compliance process design first, because sustainable compliance depends on repeatable governance, clear accountability, and consistent evidence management.

  • A. Correct.

    Correct. The first priority in a fragmented compliance environment is to establish a consolidated compliance structure that identifies applicable obligations, maps them to a common control set, assigns ownership, and defines evidence requirements. This directly addresses duplicated controls, gaps, and inconsistent audit artifacts. A unified control framework is a foundational compliance process step because it enables rationalization across overlapping requirements, improves accountability, and supports continuous monitoring and audit readiness.

  • B. Incorrect.

    Incorrect. A GRC platform can be valuable, but technology should support a defined compliance process rather than substitute for one. If the organization has not yet normalized requirements, mapped them to common controls, or assigned ownership, implementing tooling first may simply automate inconsistency and confusion. This is a common misconception: assuming automation can fix governance design problems.

  • C. Incorrect.

    Incorrect. External audits may identify deficiencies, but commissioning separate audits for each regulation before creating an integrated compliance approach would likely reinforce the existing siloed model and increase cost and duplication. Audits are a validation mechanism, not the first step in designing a sustainable compliance process. The CISO should first define the internal compliance framework and procedures that audits will later assess.

  • D. Incorrect.

    Incorrect. Executive or business-unit attestations can strengthen accountability, but certifications alone do not establish whether requirements have been consistently interpreted, mapped, controlled, and evidenced. Without a unified framework and clearly assigned control ownership, attestations may provide false assurance. This option reflects the misconception that managerial sign-off can replace a structured compliance process.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam