712-50 exam dumps

712-50 practice question 56 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 56

Single answerFollow organizational ethics

You are the newly appointed CISO of a global manufacturing company. During a quarterly review, the CEO privately asks you not to disclose a recently discovered third-party data exposure to the board until after a pending acquisition is finalized. The exposure has not yet been publicly reported, legal counsel is still assessing notification obligations, and there is no evidence of active misuse so far. The CEO argues that early disclosure could jeopardize valuation and says, "Just keep this within the executive team for now." According to sound organizational ethics and executive security leadership practice, what is the MOST appropriate action for the CISO?

  1. A

    Comply with the CEO's request because there is no confirmed misuse yet, and defer disclosure until legal obligations are clearer.

  2. B

    Document the issue, advise the CEO of the ethical and governance implications, and ensure the matter is escalated through the organization's approved governance channels, including the board or relevant board committee as required by policy.

  3. C

    Immediately disclose the incident to all employees and the public to demonstrate transparency, even before legal and forensic review is complete.

  4. D

    Resign from the role and anonymously report the matter externally, since any delay requested by the CEO is automatically unethical.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2. In a CCISO context, following organizational ethics means more than personal honesty; it requires preserving integrity in governance, risk reporting, and executive decision support. A CISO must avoid allowing business pressure, including M&A concerns, to distort reporting of material cyber risk. The appropriate response is to document the facts, communicate the implications clearly, and escalate through approved channels such as the audit committee, risk committee, general counsel, or full board depending on policy and severity.

This approach is consistent with widely accepted governance and ethics principles found in board-level security guidance and control frameworks. For example, ISO/IEC 27001 and ISO 37301 emphasize governance, accountability, and compliance-oriented decision-making; COBIT highlights stakeholder transparency, governance objectives, and escalation; and common corporate governance practice expects boards to receive timely information on material risks. The CISO should also coordinate with legal counsel, privacy, and incident response teams so that regulatory notification, evidentiary preservation, and disclosure decisions are handled properly.

The key ethical principle being tested is that senior security leaders must provide truthful, complete, and timely risk information to authorized decision-makers, even when doing so is uncomfortable or commercially inconvenient. Ethical leadership requires independence, documentation, and use of governance mechanisms rather than concealment, panic disclosure, or premature whistleblowing.

  • A. Incorrect.

    This is incorrect because absence of confirmed misuse does not remove the CISO's ethical duty to provide accurate, timely risk information through proper governance channels. A CISO should not suppress material cyber risk information solely for business optics or transaction timing. Deferring solely because the CEO prefers silence creates a conflict with fiduciary oversight, risk governance, and organizational ethics.

  • B. Correct.

    This is correct because the CISO's responsibility is to act with integrity, maintain independence of judgment, and follow established governance and reporting processes. Documenting facts, advising leadership of the ethical and risk implications, and escalating to the board or designated board committee aligns with executive accountability, due care, and transparent risk reporting. This approach also preserves legal privilege and supports proper decision-making without bypassing internal processes.

  • C. Incorrect.

    This is incorrect because ethical conduct does not mean uncontrolled disclosure. Broad internal or public disclosure before legal, privacy, and incident-response review could create unnecessary harm, spread inaccurate information, and interfere with investigation. The CISO should be transparent through authorized governance and incident-management channels, not act unilaterally outside them.

  • D. Incorrect.

    This is incorrect because while external reporting may become necessary in some circumstances, immediate resignation and anonymous reporting is not the most appropriate first step here. The CISO should first use formal internal escalation mechanisms, document concerns, and work within governance structures unless there is clear unlawful obstruction or exhaustion of reporting avenues. Choosing this option reflects a misconception that ethical leadership bypasses corporate governance rather than using it effectively.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam