712-50 exam dumps

712-50 practice question 73 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 73

Single answerEnsure that the necessary changes based on the audit findings are effectively implemented in a timely manner

An internal audit identified that several critical security control deficiencies remain unresolved more than 90 days after reporting, including delayed privileged access reviews and incomplete vulnerability remediation on internet-facing systems. The audit committee has asked the CISO to demonstrate that corrective actions will be implemented on time and that overdue items will not persist without visibility or accountability. Which action should the CISO take FIRST to most effectively ensure that audit-driven changes are implemented in a timely manner?

  1. A

    Establish a formal remediation governance process with assigned control owners, target dates, risk-based prioritization, status tracking, and escalation of overdue actions to executive leadership

  2. B

    Ask the internal audit team to take ownership of remediation activities until all findings are closed so implementation can be independently monitored

  3. C

    Delay remediation of lower-cost findings until the next annual budget cycle so that all corrective actions can be funded together

  4. D

    Close audit findings once management verbally agrees with the recommendations, provided the affected teams confirm they intend to address them

Show answer and explanation

Correct answer: A

Explanation

This scenario tests executive oversight of audit remediation rather than technical control selection. In CCISO practice, the CISO is expected to ensure that audit findings translate into accountable, time-bound corrective actions. The best response is to implement a formal remediation governance process that includes: clearly assigned owners, remediation plans, due dates, risk-based prioritization, regular reporting, evidence-based validation, and escalation of overdue items. These elements align with common governance and assurance practices reflected in frameworks such as ISO/IEC 27001 corrective action concepts, NIST guidance on continuous monitoring and POA&M-style tracking, and IIA audit follow-up expectations that management is responsible for remediation while audit independently verifies closure. The key principle is that timely implementation requires governance, accountability, and escalation, not transfer of responsibility to auditors, budget-driven delay, or closure based on management intent alone.

  • A. Correct.

    Correct. The most effective first step is to put in place a structured remediation governance mechanism that assigns accountability to business or control owners, sets due dates, prioritizes based on risk, tracks progress, and escalates missed deadlines. This is how a CISO operationalizes audit follow-up and ensures findings result in measurable change rather than passive acceptance. Timely implementation depends on ownership, reporting cadence, and escalation paths, especially for high-risk items such as privileged access and internet-facing vulnerabilities.

  • B. Incorrect.

    Incorrect. Internal audit should maintain independence and validate remediation, not become responsible for implementing or owning corrective actions. Assigning remediation ownership to audit creates a conflict with the three-lines model and undermines audit objectivity. Management, under oversight from the CISO and executive governance bodies, must own corrective action plans.

  • C. Incorrect.

    Incorrect. Deferring remediation to align with budgeting convenience is inconsistent with risk-based management, particularly for critical findings affecting exposed systems or access governance. While funding constraints can affect scheduling, high-risk issues require compensating controls, reprioritization, or escalation for risk acceptance rather than automatic delay.

  • D. Incorrect.

    Incorrect. Verbal agreement or stated intent is not evidence of remediation. Findings should only be closed after corrective actions are implemented and validated through documented evidence and, where appropriate, testing. Premature closure is a common audit follow-up weakness that leads to repeat findings and ineffective risk reduction.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam