712-50 Question 52
Single answerCompile, analyze, and report compliance programsA newly appointed CISO is preparing the quarterly compliance report for the board after the company expanded into multiple jurisdictions and must now demonstrate alignment with several regulatory and contractual requirements. Internal audit found that each business unit tracks compliance differently, resulting in duplicated controls, inconsistent evidence, and reports that focus on technical activity rather than business risk. The board has asked for a report that shows the organization's true compliance posture, key gaps, and where investment is needed. What should the CISO do FIRST to improve how the compliance program is compiled, analyzed, and reported?
- A
Create a unified control framework that maps legal, regulatory, and contractual obligations to common controls, then report compliance status and gaps against that consolidated baseline
- B
Report the number of security tools deployed and the volume of alerts handled by the security operations team as leading indicators of compliance maturity
- C
Require each business unit to continue reporting separately so the board can see detailed compliance activities for every regulation and geography
- D
Delay board reporting until every control in every jurisdiction has been independently validated to avoid presenting incomplete information
Show answer and explanation
Correct answer: A
Explanation
When an organization faces multiple regulatory, legal, and contractual obligations, the CISO should first establish a consolidated compliance structure based on a common control framework or control crosswalk. This allows the organization to compile obligations once, map them to shared controls, identify overlaps, analyze coverage and deficiencies consistently, and report results in a way that supports executive decision-making. Board reporting should translate compliance activity into business impact by highlighting control effectiveness, material gaps, risk exposure, remediation progress, and required investment. This approach aligns with widely accepted practices in governance, risk, and compliance programs, including the use of control mapping and harmonization found in frameworks and guidance such as NIST SP 800-53 control baselines and assessment concepts, the NIST Cybersecurity Framework's governance and measurement orientation, ISO/IEC 27001 requirements for monitoring, measurement, analysis, evaluation, and compliance obligations, and common GRC practices used to rationalize overlapping requirements across regimes.
- A. Correct.
This is correct because the immediate priority is to normalize and rationalize the compliance program into a common control framework. A unified framework lets the CISO compile requirements from multiple sources, map them to shared controls, identify overlaps and gaps, reduce duplicated testing, and present results in a business-relevant manner. This approach supports consistent evidence collection and enables reporting on risk, remediation priorities, and resource needs rather than disconnected compliance activities.
- B. Incorrect.
This is incorrect because operational security metrics such as tool counts or alert volumes do not reliably demonstrate compliance posture. They may indicate security activity, but they do not show whether regulatory or contractual obligations are met, whether controls are effective, or where material compliance gaps exist. A board-level compliance report should emphasize obligation coverage, residual risk, exceptions, and remediation status.
- C. Incorrect.
This is incorrect because maintaining separate reporting by business unit preserves the fragmentation that caused the problem. While some local detail may still be needed, the board requires an enterprise view of compliance posture. Separate reports make it harder to analyze common control effectiveness, compare risk consistently, and prioritize enterprise investments. This option reflects a common misconception that more detail automatically improves governance reporting.
- D. Incorrect.
This is incorrect because waiting for complete validation across every jurisdiction would delay governance reporting and reduce management's ability to make timely decisions. Board reporting often includes current status, known limitations, top risks, and remediation plans. Best practice is to provide transparent, risk-based reporting with clear assumptions and confidence levels rather than withholding information until perfect completeness is achieved.