712-50 Question 74
Single answerDomain 2: Organizational Executive Leadership (16%)A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed major weaknesses in governance, executive reporting, and business alignment. The board has asked for a 12-month security transformation plan, but several business unit leaders are already resisting, saying security has historically slowed plant modernization projects. The CEO wants the CISO to rebuild trust, obtain executive support, and ensure security investments are tied to business priorities rather than technical preferences. Which action should the CISO take FIRST to maximize executive alignment and improve the likelihood of sustained support?
- A
Develop a prioritized security strategy mapped to enterprise objectives, business risks, and measurable outcomes, then socialize it with executive leadership for sponsorship
- B
Immediately deploy additional endpoint detection and response tools across all manufacturing sites to demonstrate quick progress after the ransomware incident
- C
Require each business unit leader to accept formal accountability for all cyber risks in their area before any modernization projects are approved
- D
Create a detailed technical remediation roadmap based primarily on the incident response team's lessons learned and present it directly to the security steering committee
Show answer and explanation
Correct answer: A
Explanation
The best first step is to establish a business-aligned security strategy that executives can understand, support, and govern. In CCISO Domain 2, the CISO is expected to operate as a business leader, not just a technical manager. That means translating cyber risk into business impact, aligning initiatives to enterprise strategy, and building executive sponsorship through governance and communication. Following a significant incident, organizations often want visible action quickly, but a mature executive response balances urgency with strategic alignment. Best practices from governance and risk frameworks such as COBIT, ISO/IEC 27001, and NIST CSF emphasize aligning security objectives with business objectives, defining governance structures, and prioritizing investments based on risk and organizational context. Tactical tooling and remediation should follow from that strategy, not replace it.
- A. Correct.
Correct. In Domain 2, executive leadership requires the CISO to align the security program with organizational strategy, risk appetite, and business objectives before driving implementation. A prioritized strategy tied to measurable business outcomes helps the CISO gain credibility, secure sponsorship, and frame security as an enabler rather than an obstacle. This approach also supports effective governance, resource allocation, and communication with the board and senior leadership.
- B. Incorrect.
Incorrect. While additional detection capability may be useful, leading with a tool deployment is a tactical response, not an executive leadership action. It does not address the board's request for a transformation plan, does not rebuild cross-functional trust, and risks reinforcing the perception that security focuses on technology rather than business priorities.
- C. Incorrect.
Incorrect. Business leaders do share ownership of risk, but forcing formal accountability as the first step is likely to increase resistance and weaken collaboration. Executive leadership at the CISO level should begin with partnership, shared objectives, and governance mechanisms that clarify accountability over time rather than using accountability as an opening lever.
- D. Incorrect.
Incorrect. Lessons learned from the incident are important inputs, but a remediation roadmap driven mainly by technical findings is too narrow for the first executive action. It may improve controls, but it does not sufficiently connect security priorities to enterprise goals, strategic risk decisions, or executive sponsorship needs.