712-50 Question 80
Single answerRole of Leader in Organizational SuccessA newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weaknesses in coordination between IT, operations, legal, and business unit leaders. The CEO tells the CISO, "We already have technical controls. What we lack is leadership that aligns security with business execution." The company is launching a multi-year digital transformation program, and several executives view security as a blocker. Which action should the CISO take FIRST to demonstrate effective leadership that contributes to organizational success?
- A
Immediately mandate stricter security controls across all business units to reduce the likelihood of another incident
- B
Develop a business-aligned security strategy with executive stakeholders, defining shared objectives, risk appetite, decision rights, and measurable outcomes tied to transformation goals
- C
Outsource incident response and security operations to a managed service provider to show quick improvement in cyber resilience
- D
Focus on expanding security awareness training for all employees so the organization develops a stronger security culture
Show answer and explanation
Correct answer: B
Explanation
The scenario emphasizes that the organization's gap is not merely technical capability, but leadership that enables organizational success. At the CCISO level, the leader's role includes setting direction, aligning security with business strategy, influencing peers, establishing governance, and ensuring accountability across functions. The best first step is to build a business-aligned security strategy with executive stakeholders so that security supports enterprise objectives such as digital transformation, resilience, and operational continuity. This approach reflects widely accepted practices in executive security leadership and governance, including principles found in ISACA COBIT guidance on governance and alignment, NIST Cybersecurity Framework guidance on governance and organizational context, and ISO/IEC 27001 concepts related to leadership, organizational context, and risk-based planning. A senior security leader creates value by integrating risk decisions into business decision-making, not by leading with isolated technical mandates.
- A. Incorrect.
This is not the best first action. Mandating stricter controls without first aligning with business priorities, governance expectations, and executive ownership can reinforce the perception that security is a blocker. A CCISO-level leader is expected to influence enterprise direction, not just impose technical controls. While stronger controls may eventually be appropriate, leadership effectiveness begins with alignment, sponsorship, and governance.
- B. Correct.
This is the best answer. In a CCISO context, leadership contributes to organizational success by aligning security with business strategy, creating executive buy-in, clarifying accountability, and translating risk into business terms. Establishing shared objectives, agreed risk appetite, decision rights, and measurable outcomes enables security to support transformation instead of obstructing it. This demonstrates strategic leadership, cross-functional coordination, and governance maturity.
- C. Incorrect.
This may improve operational capability, but it does not address the core leadership problem identified by the CEO: lack of alignment and coordination among leaders. Outsourcing can be part of a delivery model, but it is not a substitute for executive leadership, governance, or stakeholder engagement. Choosing this first would focus on operational response rather than enterprise leadership.
- D. Incorrect.
Security awareness is valuable, but it is too narrow and tactical as the first leadership move in this scenario. The stated issue is executive misalignment during a business transformation, not primarily end-user behavior. A strong culture usually follows from visible leadership, governance, and business-integrated objectives rather than training alone.