712-50 exam dumps

712-50 practice question 72 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 72

Single answerEnsure that the necessary changes based on the audit findings are effectively implemented in a timely manner

An internal audit identified several high-risk security findings, including inactive privileged accounts, missing firewall rule recertification, and delayed vulnerability remediation in internet-facing systems. The CIO has agreed to remediation, but prior audits showed that corrective actions were delayed because business units treated them as informal recommendations. As the CISO, you must ensure that the necessary changes are implemented effectively and on schedule across multiple departments. Which action is the MOST effective to drive timely implementation and sustained accountability?

  1. A

    Issue a security advisory to all affected teams with the audit report attached and request weekly email updates until items are closed

  2. B

    Establish a formal remediation program that assigns control owners, risk-based deadlines, evidence requirements, and executive escalation for overdue actions through governance committees

  3. C

    Allow each department to determine its own remediation timeline because system owners best understand their operational constraints

  4. D

    Focus first on rewriting security policies to reflect the audit findings, then begin remediation after the policy update cycle is complete

Show answer and explanation

Correct answer: B

Explanation

The best answer is to establish a formal remediation program with assigned ownership, deadlines, evidence standards, and escalation paths. In executive security leadership, the challenge is not merely identifying control weaknesses through audit, but ensuring corrective action is implemented in a timely, verifiable, and sustainable way. Effective post-audit follow-up typically includes: mapping each finding to a responsible owner, classifying remediation by risk severity, defining target completion dates, requiring objective closure evidence, tracking status through a centralized issue-management process, and escalating overdue items to senior governance forums such as a risk committee or audit committee. This approach is consistent with widely accepted governance and assurance practices reflected in ISACA audit follow-up principles, the NIST Cybersecurity Framework governance and improvement concepts, and ISO/IEC 27001 expectations for corrective action and continual improvement. The key leadership principle is that audit findings must be converted into governed remediation actions, not left as advisory observations.

  • A. Incorrect.

    This is insufficient because distributing the audit report and requesting status emails does not create strong ownership, measurable accountability, or enforceable deadlines. Email-driven follow-up often results in inconsistent tracking, weak evidence collection, and limited escalation when remediation stalls. A candidate might choose this because communication is necessary, but communication alone does not ensure effective implementation of audit-driven change.

  • B. Correct.

    This is correct because a formal remediation program operationalizes audit findings into accountable actions. Assigning owners ensures responsibility; risk-based deadlines prioritize high-impact findings; evidence requirements confirm that remediation is completed rather than merely reported; and executive escalation creates pressure and governance visibility for overdue items. This approach aligns with mature security governance and audit follow-up practices by integrating remediation into enterprise oversight rather than treating findings as informal recommendations.

  • C. Incorrect.

    This is incorrect because although operational constraints matter, allowing each department to set its own timeline without centralized governance weakens consistency and can leave high-risk findings unresolved for too long. Business units may deprioritize security in favor of operational goals, which is a common root cause of repeated audit findings. Risk treatment can involve adjusted timelines, but those should be formally reviewed, approved, and tracked rather than left entirely to departmental discretion.

  • D. Incorrect.

    This is incorrect because policy updates may be appropriate, but delaying remediation until policies are rewritten is a poor response to known high-risk findings. Audit issues such as privileged account cleanup and vulnerability remediation typically require immediate corrective action. A candidate might select this because policies are foundational, but policy revision should support remediation, not postpone it.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam