712-50 Question 6
Single answerA newly appointed CISO at a global manufacturing company finds that business units are independently selecting security tools, approving exceptions, and defining risk tolerances. Audit reports show inconsistent control implementation across regions, and the board has asked for clearer accountability and reporting on cyber risk. The CEO supports improving security oversight but does not want to slow down business operations with excessive centralization. Which action should the CISO take FIRST to establish an effective information security governance program?
- A
Deploy a standardized enterprise security toolset across all business units to enforce consistent technical controls immediately
- B
Create a security governance charter that defines decision rights, roles, reporting lines, risk ownership, and escalation processes, and obtain executive approval
- C
Require each business unit leader to submit monthly security metrics before any governance structure is formalized
- D
Centralize all security decisions under the CISO's office and remove business unit authority for risk-based exceptions
Show answer and explanation
Correct answer: B
Explanation
The core issue in the scenario is not primarily technology inconsistency; it is weak governance characterized by unclear authority, fragmented decision-making, and undefined accountability. In CCISO practice, the CISO's first responsibility is to establish a governance framework that aligns security with business objectives and defines leadership roles, organizational structures, and decision processes. A governance charter or equivalent formal document typically sets scope, authority, committee structure, risk ownership, exception management, reporting cadence, and escalation paths. This provides the foundation for subsequent activities such as metrics, policy harmonization, and technology standardization.
This approach is consistent with widely recognized governance principles in frameworks such as COBIT, which emphasizes governance structures, decision rights, and alignment with enterprise goals, and ISO/IEC 27014, which focuses on the governance of information security through direction, monitoring, evaluation, and communication. ISO/IEC 27001 also supports assigning roles and responsibilities and ensuring top-management direction. The best answer therefore is to first formalize governance with executive sponsorship rather than start with tools, ad hoc reporting, or excessive centralization.
- A. Incorrect.
This is not the best first step. Standardizing tools may improve control consistency, but governance problems stem from unclear authority, roles, and accountability. Implementing technology before defining governance can lead to resistance, poor adoption, and continued confusion about who owns risk decisions.
- B. Correct.
This is correct. An effective information security governance program begins with formally establishing leadership, organizational structures, and decision-making processes. A governance charter clarifies accountability, defines who owns risk, specifies how exceptions are approved, and creates reporting and escalation paths. Executive approval is critical because governance must be aligned to enterprise objectives and supported from the top.
- C. Incorrect.
This is premature. Metrics and reporting are important elements of governance, but requiring reporting before defining governance roles, accountability, and decision rights often produces inconsistent or low-value data. The organization first needs a clear structure for what will be measured, who is accountable, and how information will be used.
- D. Incorrect.
This is a common overcorrection and is not the best answer. Governance does not require eliminating business participation in decision-making. In mature governance models, business leaders retain ownership of business risk while security provides policy, oversight, and guidance. Over-centralization may conflict with the CEO's concern about slowing operations and can weaken business accountability for risk.