712-50 Question 77
Single answerRole of Leader (6 questions)A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, legal, operations, and executive management. The CEO tells the CISO, "I need you to make security part of how leaders run the business, not just an IT issue." The company has competent technical staff, but business unit heads see security as a compliance hurdle and frequently bypass controls to meet production deadlines. As a leader, which action should the CISO take FIRST to create lasting organizational alignment with the CEO's objective?
- A
Implement stricter technical controls immediately and require security approval for all operational changes
- B
Develop and communicate a business-aligned security vision, establish governance with executive stakeholders, and define shared accountability for risk decisions
- C
Outsource security operations to a managed security service provider so business leaders can focus on production goals
- D
Launch mandatory security awareness training for all employees and track course completion by department
Show answer and explanation
Correct answer: B
Explanation
The best answer is to establish a business-aligned security vision and governance structure with executive stakeholders. In the CCISO domain, the role of leader requires influencing organizational culture, aligning security objectives with business strategy, and creating accountability beyond the security team. After a major incident, a mature CISO should avoid responding only with technical or compliance-centric measures. Instead, the CISO should engage senior leadership, define risk ownership, and ensure that operational decisions reflect agreed business risk tolerance. This approach aligns with widely accepted practices in security leadership and governance, including principles reflected in NIST CSF governance outcomes, ISO/IEC 27001 leadership and organizational context requirements, and general governance guidance such as COBIT, all of which emphasize executive involvement, accountability, and alignment of security with enterprise objectives.
- A. Incorrect.
This is a plausible reaction after a ransomware incident, but it is not the best first leadership action. Tightening controls without executive alignment often increases resistance, reinforces the perception that security is obstructive, and fails to address the underlying governance and culture problem. In a CCISO leadership context, the CISO must first build sponsorship, shared ownership, and decision-making structures before imposing broad operational constraints.
- B. Correct.
This is correct because the scenario is primarily about leadership, culture, and enterprise alignment rather than a lack of technical capability. A CISO acting as a leader should translate security into business terms, articulate how security supports resilience and operational continuity, and create governance mechanisms that involve business executives in prioritization and risk acceptance. Shared accountability helps move security from an isolated IT function to an enterprise responsibility, which is exactly what the CEO requested.
- C. Incorrect.
This may improve operational capability in some environments, but it does not solve the core issue that internal leaders treat security as someone else's problem. Outsourcing can supplement execution, but leadership accountability, governance, and culture cannot be delegated to a third party. Choosing this first would confuse operational support with organizational leadership.
- D. Incorrect.
Security awareness training is useful, but it is too tactical and too broad as the first leadership move in this scenario. The problem described is not primarily employee ignorance; it is executive and business-unit behavior driven by conflicting incentives. Without leadership alignment, training completion metrics may look positive while business leaders continue bypassing controls.