712-50 exam dumps

712-50 practice question 82 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 82

Single answerRole of Leader in Information Security

A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, legal, operations, and executive leadership. The CEO asks the CISO to "make security part of how leaders run the business, not just an IT function." The company already has basic security tools, but business unit heads still view security as a blocker and rarely participate in risk discussions. As a security leader, which action should the CISO take FIRST to establish effective leadership in information security at the enterprise level?

  1. A

    Implement stricter technical controls immediately across all business units to demonstrate rapid security improvement

  2. B

    Establish executive governance by creating a cross-functional security steering committee with defined risk ownership, reporting, and decision-making authority

  3. C

    Outsource incident response and security operations to a managed security service provider so executives can focus on business priorities

  4. D

    Require all employees to complete mandatory security awareness training before involving business leaders in security planning

Show answer and explanation

Correct answer: B

Explanation

In the CCISO context, the role of the leader in information security is to drive governance, influence executive behavior, align security with business objectives, and assign risk ownership across the enterprise. The scenario shows that the company already has technical capabilities, but security is not embedded in leadership decision-making. Therefore, the most appropriate first action is to establish executive governance through a cross-functional steering structure.

This approach is consistent with widely accepted practices in information security governance. NIST's Cybersecurity Framework emphasizes governance, risk management, and organizational roles in managing cybersecurity outcomes. ISO/IEC 27001 and ISO/IEC 27014 also stress leadership commitment, assignment of responsibilities, and integration of information security into organizational processes. From a governance perspective, COBIT similarly reinforces that enterprise leaders must evaluate, direct, and monitor security-related risk and control objectives.

A mature CISO does not lead primarily by deploying more tools; the CISO leads by creating accountability, translating technical risk into business terms, and ensuring that business leaders participate in prioritization and decision-making. Once governance is in place, technical controls, awareness programs, and external service providers can be evaluated and implemented in a way that supports enterprise risk management rather than operating in isolation.

  • A. Incorrect.

    This is not the best first action. Although stronger technical controls may be necessary after a ransomware event, the scenario highlights a leadership and governance failure: weak coordination, lack of business ownership, and executives viewing security as an IT problem. A CCISO-level leader should first establish the governance structure that aligns security with enterprise risk and business decision-making. Implementing controls before securing leadership engagement often reinforces the perception that security is merely a technical enforcement function.

  • B. Correct.

    This is the best answer. The core issue is not a lack of tools but a lack of enterprise leadership, accountability, and cross-functional decision-making. A cross-functional security steering committee led with executive sponsorship helps the CISO embed security into business governance, clarify risk ownership, prioritize investments, and ensure operations, legal, HR, finance, and business leaders participate in security decisions. This reflects the role of a security leader as an influencer, strategist, and business enabler rather than only a technical manager.

  • C. Incorrect.

    This is a plausible but incomplete response. Outsourcing operational capabilities may improve response execution, but it does not solve the stated leadership problem: business leaders are disengaged and security lacks enterprise integration. Managed services can support capability gaps, but the CISO's first priority should be to build governance and accountability within the organization. Otherwise, the company may improve technical handling while continuing to suffer from poor executive ownership and business alignment.

  • D. Incorrect.

    Security awareness training is valuable, but making it the first step misses the organizational issue. The scenario is specifically about executive and business-unit leadership failing to participate in risk discussions. Enterprise security culture starts with tone from the top and governance mechanisms, not solely with employee training. Training without leadership accountability often results in compliance activity rather than meaningful business integration of security.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam