712-50 Question 88
Single answerLeadership EnvironmentsA newly appointed CISO joins a global manufacturing company that has grown through acquisitions. Each business unit has its own IT leadership, risk tolerance, and informal security practices. After a recent ransomware incident, the CEO asks the CISO to improve security quickly without disrupting plant operations or creating resistance from regional executives. In this leadership environment, which action should the CISO take FIRST to create sustainable enterprise-wide alignment?
- A
Issue a mandatory enterprise security standard immediately and require all business units to comply within 30 days
- B
Begin by mapping key stakeholders, understanding business priorities and risk appetite across business units, and establishing a governance forum to align security objectives with enterprise goals
- C
Centralize all security decision-making under the CISO organization and remove local IT leaders from security-related decisions
- D
Delay governance discussions until a full technical control assessment is completed so recommendations are based only on objective data
Show answer and explanation
Correct answer: B
Explanation
This question tests the candidate's ability to lead in a complex organizational environment, not merely design controls. In CCISO leadership environments, the CISO must adapt to organizational culture, governance maturity, and business operating models. In decentralized or acquisition-driven enterprises, the first priority is usually to understand stakeholders, define governance, clarify accountability, and align security strategy with enterprise objectives. This is consistent with widely accepted security leadership practices reflected in governance-focused frameworks such as ISACA COBIT, the NIST Cybersecurity Framework governance emphasis, and ISO/IEC 27001's requirement for leadership commitment, organizational roles, and alignment with business context. Effective CISOs build influence through governance structures and business alignment before enforcing broad operational change.
- A. Incorrect.
This is not the best first action. While enterprise standards are important, imposing them immediately in a fragmented, acquisition-heavy environment often creates resistance, especially where operational continuity is critical. A 30-day compliance deadline is unrealistic for diverse manufacturing sites and does not address differences in business priorities, risk ownership, or leadership culture. This reflects a common mistake of treating leadership alignment as a policy enforcement problem rather than a governance and change-management challenge.
- B. Correct.
This is the best answer. In a complex leadership environment, a CISO should first understand stakeholders, decision rights, business drivers, and varying risk tolerances before pushing enterprise controls. Establishing a governance forum helps align security with business strategy, creates executive sponsorship, and enables shared accountability across regions and business units. This approach is especially appropriate after mergers or acquisitions, where influence, consensus-building, and clear governance are essential for sustainable change.
- C. Incorrect.
This is incorrect because it over-centralizes authority and ignores the realities of federated organizations. Local IT and business leaders often own operational processes and risks that the security function cannot manage effectively in isolation. Excluding them may speed decisions in the short term but usually weakens adoption, reduces local ownership, and can cause operational friction. The misconception here is that stronger authority automatically produces better security outcomes; in practice, executive leadership requires collaboration, not just control.
- D. Incorrect.
This is not the best first step because leadership and governance issues should not wait for a full technical assessment. Technical findings are useful, but without stakeholder alignment and agreed decision-making mechanisms, even accurate findings may not be acted upon effectively. In a post-incident environment, the CISO needs to establish trust, priorities, and governance quickly. This option reflects the misconception that technical analysis alone can solve organizational leadership challenges.