712-50 Question 87
Single answerLeadership Types, Styles, and TheoriesA newly appointed CISO inherits a security organization that has strong technical specialists but poor collaboration with application development, infrastructure, and business unit leaders. Recent audit findings show repeat control failures because teams implement fixes only when directed, and they rarely raise risks proactively. The CEO asks the CISO to improve security culture without slowing digital transformation. Which leadership approach would BEST help the CISO increase long-term ownership of security outcomes across teams?
- A
Adopt a transformational leadership style that communicates a clear security vision, aligns security goals with business objectives, and empowers managers to take ownership of risk reduction
- B
Use a transactional leadership style centered on strict corrective actions and compliance scorecards for every missed control, with escalation to HR for repeated failures
- C
Apply a laissez-faire leadership style so technical teams can independently determine how much security oversight is necessary for their environment
- D
Rely on an authoritarian leadership style to centralize all security decisions within the CISO office until audit issues are fully eliminated
Show answer and explanation
Correct answer: A
Explanation
The best answer is the transformational leadership approach because the scenario is fundamentally about culture change, empowerment, and strategic alignment. In CCISO practice, senior security leaders are expected not only to enforce controls but also to influence business leaders, create accountability, and embed security into organizational behavior. Transformational leadership supports this by establishing a compelling vision, motivating stakeholders, and developing people to own outcomes. By contrast, transactional and authoritarian approaches may help in limited circumstances such as urgent remediation or baseline control enforcement, but they do not best address the root issue of low initiative and poor collaboration. Laissez-faire leadership is typically unsuitable where governance weaknesses and repeat audit findings already exist. This aligns with widely accepted leadership theory and security governance best practices reflected in frameworks such as NIST Cybersecurity Framework governance outcomes, NIST SP 800-53 control families related to governance and organizational processes, and ISO/IEC 27001 leadership expectations requiring top management direction, alignment, and continual improvement.
- A. Correct.
Correct. Transformational leadership is most appropriate when the goal is to change culture, improve cross-functional collaboration, and create sustained ownership rather than short-term compliance. In this scenario, the organization is technically capable but lacks initiative, shared accountability, and alignment with business priorities. A transformational CISO would articulate why security matters to business success, motivate teams around a common vision, and develop leaders across IT and business functions. This approach is especially effective for improving maturity in environments undergoing digital transformation because it encourages engagement and proactive risk management rather than mere rule-following.
- B. Incorrect.
Incorrect. Transactional leadership can be useful for enforcing specific expectations, measuring performance, and correcting immediate compliance gaps. However, by itself it is less effective for building a durable security culture or encouraging proactive collaboration across departments. In this scenario, repeat findings already suggest teams are acting only when directed. Increasing reliance on punishment, scorecards, and escalations may improve short-term adherence but is unlikely to create the long-term ownership and initiative the CEO is seeking.
- C. Incorrect.
Incorrect. Laissez-faire leadership generally provides too little direction and oversight for a function like enterprise security, especially where repeat control failures and weak cross-functional accountability already exist. While empowered teams are valuable, this style would likely worsen inconsistency and leave unresolved ambiguity about risk ownership, governance, and minimum control expectations.
- D. Incorrect.
Incorrect. An authoritarian style may produce rapid decisions during crisis conditions, such as an active incident response or urgent regulatory deadline, but it is not the best fit for improving culture and distributed accountability over time. Centralizing all decisions in the CISO office can create bottlenecks, reduce business engagement, and reinforce the very dependency problem described in the scenario, where teams act only when explicitly instructed.