712-50 exam dumps

712-50 practice question 8 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 8

Single answer

A newly appointed CISO joins a global consumer technology company that is rapidly expanding through acquisitions. The CEO promotes a decentralized, innovation-driven culture and has historically allowed business units to make independent technology decisions. After a recent acquisition, the board asks the CISO to establish a security governance framework that improves risk oversight without undermining the organization’s entrepreneurial operating model. Which action should the CISO take FIRST to best align the information security governance framework with organizational goals and governance?

  1. A

    Implement a single, enterprise-wide set of detailed security procedures immediately and require all business units to adopt them within 90 days

  2. B

    Begin by mapping business objectives, decision-making authority, and risk appetite to a federated security governance model with enterprise security principles and minimum control requirements

  3. C

    Prioritize deployment of a centralized security toolset across all acquired entities so governance decisions can be enforced consistently

  4. D

    Adopt the governance framework used by the most mature acquired company because it has already proven effective in a similar industry

Show answer and explanation

Correct answer: B

Explanation

The best first step is to design security governance based on how the organization is governed and how it creates value. In this scenario, the company has a decentralized, innovation-oriented culture and is growing through acquisitions. The CISO should therefore begin by understanding business objectives, board expectations, management decision rights, and enterprise risk appetite, then translate those into a governance model that balances autonomy with oversight. A federated governance model is often effective in such environments: the enterprise establishes security principles, policy requirements, minimum control baselines, and reporting/escalation mechanisms, while business units retain flexibility in implementation where appropriate. This aligns with widely accepted governance practices reflected in frameworks such as COBIT, ISO/IEC 27014, and ISO/IEC 27001, which emphasize that information security governance should support organizational objectives, integrate with corporate governance, define accountability, and operate according to risk management principles. The key exam concept is that governance must be aligned to leadership style, philosophy, values, standards, and policies before selecting tools or enforcing detailed procedures.

  • A. Incorrect.

    This is incorrect because it starts with prescriptive standardization before understanding the organization's governance style, business strategy, and delegated decision rights. In a decentralized company, forcing uniform detailed procedures too early can create resistance, reduce agility, and misalign security with how the organization actually operates. A CISO should first establish governance principles, accountability, and risk-based minimum expectations rather than immediately imposing one operating model everywhere.

  • B. Correct.

    This is correct because it aligns security governance to the organization's leadership philosophy, operating model, and risk appetite before defining how control should be exercised. A federated approach is often appropriate where business units retain autonomy, while enterprise-level principles, minimum baselines, and escalation paths ensure consistent oversight. This approach supports business objectives, respects existing decision-making structures, and enables integration of acquisitions without unnecessary disruption.

  • C. Incorrect.

    This is incorrect because tooling is an implementation mechanism, not the starting point for governance alignment. Centralized tools may help operationalize standards later, but they do not by themselves define authority, accountability, policy hierarchy, or acceptable risk. Choosing technology first is a common mistake when governance design should be driven by business goals and corporate governance expectations.

  • D. Incorrect.

    This is incorrect because copying another entity's framework without validating fit to the parent company's culture, leadership style, values, and governance structure can create misalignment. Even a mature framework may be unsuitable if it assumes a different operating model, risk tolerance, or decision structure. Governance should be tailored to the enterprise context, not inherited based solely on perceived maturity.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam