712-50 exam dumps

712-50 practice question 7 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 7

Single answer

A newly appointed CISO joins a global manufacturing company that has grown through acquisitions. The board emphasizes operational efficiency, delegated decision-making in regional business units, and rapid integration of acquired companies. However, the current security program is highly centralized, requires headquarters approval for most exceptions, and enforces identical controls across all subsidiaries regardless of risk or legal requirements. Business leaders complain that security is slowing integration and conflicting with the company’s management philosophy. What is the BEST action for the CISO to align the information security governance framework with organizational goals and governance?

  1. A

    Redesign the security governance model to define enterprise-wide minimum control standards, assign accountability to regional and business-unit leaders through a federated governance structure, and allow risk-based local policies and exceptions within board-approved risk appetite

  2. B

    Maintain the centralized governance model but accelerate exception handling by adding more headquarters security reviewers and shortening approval timelines

  3. C

    Allow each acquired company to keep its existing security policies indefinitely so integration speed is not affected, provided local management accepts the risk

  4. D

    Replace most formal security policies with advisory guidelines so regional leaders can make decisions without governance constraints

Show answer and explanation

Correct answer: A

Explanation

The scenario tests whether the candidate can align security governance with the enterprise’s business strategy, management philosophy, and decision-making culture. In CCISO practice, governance is not just about imposing controls; it is about ensuring security enables organizational objectives while operating within approved risk appetite. A company that values delegated authority and rapid integration is often better served by a federated security governance model rather than a purely centralized one. In such a model, the board and executive leadership set direction, risk appetite, and mandatory baseline requirements, while business units or regions are accountable for implementation and localized procedures within that framework.

This approach is consistent with widely accepted governance and risk management practices. ISO/IEC 27014 emphasizes that information security governance should support organizational objectives and integrate with overall corporate governance. COBIT also stresses alignment of IT and security-related governance with enterprise goals, stakeholder needs, and governance structures. ISO/IEC 27001 supports the use of organization-wide policies with risk-based selection of controls, while allowing context-specific implementation. The best answer therefore preserves enterprise control through minimum standards and oversight, but adapts authority, accountability, and policy structure to match the organization’s leadership style, values, and operating model.

  • A. Correct.

    This is the best answer because it aligns security governance with the organization’s leadership style, operating model, and business objectives while preserving enterprise oversight. A federated model fits an organization with delegated decision-making across regions and business units. Establishing enterprise minimum standards maintains consistency for core requirements, while allowing risk-based local policies addresses differing legal, operational, and acquisition-integration realities. Tying local exceptions to board-approved risk appetite ensures governance remains aligned with corporate oversight rather than becoming fragmented.

  • B. Incorrect.

    This is plausible because it attempts to reduce friction, but it does not address the root governance misalignment. The issue is not simply process speed; it is that the governance structure itself conflicts with the company’s decentralized management philosophy and acquisition-driven operating model. Adding reviewers may improve throughput, but it preserves a centrally controlled framework that business leaders already see as inconsistent with organizational goals.

  • C. Incorrect.

    This is incorrect because it sacrifices enterprise governance and creates inconsistent control environments across the company. While temporary transitional arrangements may be appropriate during integration, allowing acquired entities to keep legacy policies indefinitely undermines standardization, board oversight, and risk transparency. It also makes it difficult to ensure compliance with enterprise expectations, shared services security, and consolidated risk reporting.

  • D. Incorrect.

    This is incorrect because reducing formal policies to nonbinding guidance weakens governance rather than aligning it. Organizations need enforceable policies, standards, and accountability structures to translate leadership values and risk appetite into consistent action. Flexibility should be achieved through a structured governance model, not by removing policy authority.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam