712-50 exam dumps

712-50 practice question 89 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 89

Single answerLeadership Environments

A newly appointed CISO joins a global manufacturing company where security is viewed primarily as an IT function. Business unit leaders frequently bypass security review to meet aggressive product launch deadlines, and the board has recently asked management to improve cyber resilience after a competitor suffered a major ransomware incident. The CISO has limited political capital and must establish a leadership environment that will improve long-term security outcomes without being seen as a barrier to the business. What should the CISO do FIRST?

  1. A

    Mandate that all business initiatives obtain formal security approval before funding is released, and escalate noncompliance directly to the board

  2. B

    Develop relationships with executive and business leaders, align security objectives to business priorities, and establish a risk-based governance forum with clear accountability

  3. C

    Launch an enterprise-wide technical control modernization program to quickly close security gaps and demonstrate immediate action

  4. D

    Transfer ownership of security risk decisions to the CIO so business units can continue operating without direct security involvement

Show answer and explanation

Correct answer: B

Explanation

This question tests whether the candidate understands that in leadership environments, the CISO must lead through influence, governance, and business alignment rather than relying first on technical action or coercive authority. In many organizations, especially those where security has historically been treated as an IT support function, the central challenge is not the absence of controls but the absence of shared ownership and executive engagement. The most effective first move is to build relationships, connect security to business drivers, and create a governance mechanism that enables transparent, risk-based decisions. This reflects widely accepted practices in security leadership and governance, including principles found in NIST Cybersecurity Framework governance outcomes, COBIT governance and management objectives, and enterprise risk management guidance such as COSO. A mature leadership environment requires clear accountability, stakeholder buy-in, and integration of security into business decision-making.

  • A. Incorrect.

    This is not the best first step. While stronger governance and escalation paths may eventually be needed, immediately imposing a rigid approval gate and escalating to the board is likely to create resistance, especially when the CISO has limited political capital. In a leadership environment where security is seen as an obstacle, unilateral mandates can weaken trust and reduce cooperation. Effective executive security leadership typically begins with stakeholder alignment, governance design, and shared accountability before strict enforcement mechanisms are introduced.

  • B. Correct.

    This is the best answer. In a weak leadership environment, the CISO's first priority is to build influence, credibility, and alignment. By engaging executive and business leaders, the CISO can frame security in terms of business resilience, operational continuity, regulatory exposure, and strategic objectives. Establishing a risk-based governance forum creates a structured mechanism for decision-making, clarifies accountability, and helps shift security from an IT issue to an enterprise risk issue. This approach is consistent with executive security leadership practices, enterprise risk management principles, and governance models such as COBIT and NIST CSF governance concepts.

  • C. Incorrect.

    This is a plausible but incomplete response. Modernizing technical controls may be necessary, especially after visible industry ransomware events, but it does not address the root leadership problem: lack of business alignment and weak governance. Without executive buy-in and agreed risk ownership, technical initiatives may be underfunded, bypassed, or misaligned with the organization's strategic priorities. A CCISO-level leader should first shape the leadership environment so security improvements can be sustained.

  • D. Incorrect.

    This is incorrect because it weakens the CISO's role and confuses accountability. Security risk is an enterprise concern that should be informed by the CISO, business leadership, and governance structures, not simply shifted to the CIO for convenience. Doing so reinforces the mistaken belief that security is only an IT matter and undermines the board's request to improve resilience. Risk decisions should be owned by the appropriate business leaders within an enterprise governance framework, with the CISO acting as a strategic advisor and control leader.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam