712-50 Question 76
Single answerRole of Leader (6 questions)A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, legal, plant operations, and executive leadership. The board asks the CISO to improve cyber resilience, but several business unit leaders view security as an IT-only function and resist participating in cross-functional planning. As a leader, what should the CISO do FIRST to build the organizational support needed for a sustainable security program?
- A
Mandate enterprise-wide security controls immediately and require all business units to comply with the security team's standards within 30 days
- B
Develop relationships with executive and business leaders, align security objectives to business priorities, and establish a governance structure with clear accountability
- C
Outsource major security functions to a managed security provider so the organization can quickly improve controls without depending on internal stakeholders
- D
Begin by deploying advanced technical tools for endpoint detection and network segmentation to demonstrate quick wins to the board
Show answer and explanation
Correct answer: B
Explanation
This question tests the CCISO candidate's understanding of leadership as distinct from purely technical management. In a fragmented organization, the CISO's first responsibility is to act as an enterprise leader: build executive relationships, create a shared vision, align security with business objectives, and establish governance for decision-making and accountability. This reflects widely accepted practices in security leadership and governance, including principles found in NIST Cybersecurity Framework governance outcomes, ISO/IEC 27001 leadership and organizational context requirements, and COBIT governance concepts. A mature security program depends on tone from the top, stakeholder engagement, and clearly assigned ownership across business, legal, operations, and technology functions. Technical controls and external providers can support the program, but they are not substitutes for leadership.
- A. Incorrect.
This is not the best first step. While setting standards is part of a CISO's role, imposing controls without first establishing executive alignment, governance, and business ownership often increases resistance and reinforces the misconception that security is only an IT issue. Effective leadership requires influence, coalition-building, and shared accountability before broad mandates are likely to succeed.
- B. Correct.
This is correct. In the role of leader, the CISO must influence across the enterprise, build trust with stakeholders, translate security into business terms, and create governance mechanisms that assign roles and accountability. Establishing cross-functional governance and aligning security objectives to operational and strategic priorities creates the foundation for resilience, investment support, and sustainable culture change.
- C. Incorrect.
This is incorrect as a first leadership action. Managed services can support capability gaps, but outsourcing does not solve the underlying leadership challenge of weak business ownership and poor coordination. Without internal governance and executive engagement, third-party services may improve operations tactically but will not create enterprise-wide commitment or decision-making discipline.
- D. Incorrect.
This is a plausible but incomplete response. Quick technical improvements may reduce some risk, but they do not address the core problem described: lack of cross-functional engagement and leadership alignment. A CISO operating at the executive level should first establish sponsorship, governance, and business accountability so that technical initiatives are prioritized, funded, and adopted effectively.