712-50 exam dumps

712-50 practice question 83 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 83

Single answerRole of Leader in Information Security

A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, legal, operations, and business leadership. The CEO wants the CISO to "take charge of security" but also expects plant managers and regional executives to remain accountable for business operations. During the first executive steering committee meeting, several leaders argue that security decisions should be left entirely to the security team to avoid confusion. What should the CISO do FIRST to demonstrate effective leadership in information security while improving enterprise accountability?

  1. A

    Establish and communicate a governance model that defines security roles, decision rights, risk ownership, and escalation paths across business and support functions

  2. B

    Centralize all security-related decisions under the CISO's office so that business leaders cannot override technical security requirements

  3. C

    Delay governance changes until a full technical control assessment is completed, since leadership structures should be based only on confirmed control gaps

  4. D

    Require each business unit head to sign off on all security incidents and exceptions immediately, even before responsibilities and criteria are formally defined

Show answer and explanation

Correct answer: A

Explanation

The best answer is to establish and communicate a governance model. In CCISO-level leadership, the CISO's role is not simply to operate security tools or make every decision personally, but to lead the enterprise security program through governance, influence, accountability, and alignment with business objectives. After a cross-functional failure such as a ransomware incident, the first priority is clarifying decision rights, risk ownership, and escalation mechanisms so that the organization can act coherently.

This reflects widely accepted best practices in security and risk governance. Frameworks such as NIST Cybersecurity Framework 2.0 emphasize governance as a foundational function, including organizational roles, responsibilities, and risk management expectations. ISO/IEC 27001 and ISO/IEC 27014 also support assigning information security responsibilities and integrating governance into organizational leadership structures. From a practical CCISO perspective, effective leaders ensure that security is embedded into enterprise governance rather than isolated within the security department. The CISO provides leadership, strategy, and oversight, while business leaders remain accountable for the risks tied to their mission, operations, and resources.

  • A. Correct.

    Correct. An effective information security leader creates clarity, not dependency. The CISO should first establish governance that defines who owns risk, who makes which decisions, and how issues are escalated. This aligns security with business accountability and supports coordinated action across IT, legal, operations, and executives. In mature organizations, the CISO leads the program, but business leaders retain ownership of business risk within their areas.

  • B. Incorrect.

    Incorrect. This is a common but ineffective approach that confuses leadership with control centralization. While the CISO should provide direction, standards, and risk visibility, enterprise risk ownership cannot be transferred wholesale to the security function. Business executives remain accountable for decisions affecting their operations, budgets, and risk acceptance.

  • C. Incorrect.

    Incorrect. Waiting for a technical assessment delays the leadership action most needed after the incident: clear governance and accountability. Although technical assessments are important, the scenario highlights a coordination and decision-making failure. Governance can and should be defined early so remediation and future decisions occur within an agreed leadership structure.

  • D. Incorrect.

    Incorrect. Requiring immediate sign-off without first defining roles, thresholds, and approval criteria creates confusion and may lead to inconsistent or uninformed decisions. Accountability must be structured through documented governance, not imposed administratively without context.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam