712-50 Question 79
Single answerWhy Leadership MattersA newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, legal, operations, and executive management. The board is willing to fund security improvements, but several business unit leaders still view security as an IT problem that slows production. The CEO asks the CISO to recommend the most effective first step to improve the organization's long-term cyber resilience. Which action best demonstrates why leadership matters in this situation?
- A
Implement a stricter endpoint protection standard immediately across all plants, even if business leaders are not yet aligned on priorities
- B
Establish an executive-level cyber governance forum led by senior business leadership to align risk decisions, accountability, and resilience objectives across functions
- C
Delegate security ownership to plant IT managers since they understand local operational constraints better than executives do
- D
Focus first on rewriting all security policies so employees have clearer technical instructions during incidents
Show answer and explanation
Correct answer: B
Explanation
This question tests a core CCISO principle: leadership matters because cybersecurity resilience depends on enterprise governance, culture, and accountability, not just technical controls. In this scenario, the ransomware incident revealed a leadership and coordination gap across business functions. The CISO's most effective first step is to establish executive-level governance so cyber risk is managed as a business issue. This aligns with widely accepted practices from NIST Cybersecurity Framework 2.0, which emphasizes governance as a foundational function, and with board-level guidance from organizations such as NIST, ISACA, and ISO/IEC 27014, all of which stress leadership oversight, accountability, and alignment of security with organizational objectives. A chief information security officer must influence executives, define decision rights, and create shared ownership across the enterprise. Technical controls, local delegation, and policy updates may all have value, but without visible leadership and governance they rarely produce durable, organization-wide resilience.
- A. Incorrect.
This is not the best answer because it emphasizes a technical control before establishing leadership alignment, governance, and shared accountability. While endpoint protection may be valuable, the scenario highlights a broader organizational failure involving multiple functions and a perception that security is only an IT issue. A CCISO must lead at the enterprise level, ensuring business leaders own risk decisions. Implementing controls without leadership buy-in often results in resistance, inconsistent adoption, and weak resilience.
- B. Correct.
This is the best answer because it addresses the root cause: lack of enterprise leadership, cross-functional coordination, and executive ownership of cyber risk. In a post-incident environment, the CISO should elevate cybersecurity from a technical issue to a business risk management issue. An executive governance forum helps define risk appetite, assign accountability, prioritize investments, and coordinate decisions across operations, legal, finance, HR, and IT. This reflects the CCISO expectation that leaders build culture, influence decision-makers, and align security strategy with business objectives rather than relying only on technical measures.
- C. Incorrect.
This is incorrect because it pushes responsibility downward and reinforces the misconception that cybersecurity can be managed effectively as a local IT function. Plant IT managers are important stakeholders, but they cannot set enterprise risk priorities, resolve business trade-offs, or create cross-functional accountability. The scenario specifically shows that leadership failure at senior levels contributed to poor resilience. Effective cybersecurity leadership requires executive sponsorship and enterprise-wide governance.
- D. Incorrect.
This is not the best answer because policy clarity alone does not solve the core problem of fragmented leadership and lack of business ownership. Policies are important, but they are only one mechanism of control. Without executive support, governance, and accountability, revised policies may be ignored or applied inconsistently. Candidates who choose this option may be overvaluing documentation and undervaluing leadership's role in driving culture, decision-making, and coordinated response.