712-50 exam dumps

712-50 practice question 9 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 9

Single answerEstablish information security management structure

A newly appointed CISO at a global manufacturing company finds that information security responsibilities are fragmented across IT operations, legal, privacy, internal audit, and business units. Security incidents are escalating, business leaders complain that decisions are inconsistent, and regional teams are implementing their own controls without central oversight. The CEO asks the CISO to establish an information security management structure that improves accountability while preserving business agility. Which action should the CISO take FIRST to create an effective governance structure?

  1. A

    Implement a centralized security operations center (SOC) and require all regions to route incidents through it

  2. B

    Define and approve a formal security governance model with clear roles, reporting lines, decision rights, and accountability across corporate and regional functions

  3. C

    Delegate security ownership entirely to regional business units so that controls can be tailored to local operational needs

  4. D

    Ask internal audit to take responsibility for enforcing compliance with security policies across the enterprise

Show answer and explanation

Correct answer: B

Explanation

The scenario points to a governance failure rather than a purely technical or operational one. In CCISO practice, establishing the information security management structure begins with defining governance: who is accountable, who has authority to make decisions, how security integrates with business units, and how regional variation is managed within enterprise risk tolerance. A formal governance model commonly includes steering committees, reporting lines to executive leadership, role definitions such as control owners and risk owners, and documented decision rights. This aligns with widely recognized practices from ISO/IEC 27001 and ISO/IEC 27014, which emphasize leadership, organizational roles, responsibilities, authorities, and governance of information security. It is also consistent with NIST guidance that stresses assigning security roles and integrating risk management responsibilities into organizational structures. Once governance is defined, the CISO can implement operating mechanisms such as a SOC, policy lifecycle, metrics, and regional execution models in a controlled and accountable way.

  • A. Incorrect.

    This is not the best first step. A SOC may improve monitoring and incident handling, but it is an operational capability, not a governance structure. Without first establishing who owns decisions, how responsibilities are assigned, and how regional and corporate teams interact, a centralized SOC may create more confusion and resistance. Candidates may choose this because incident escalation is a visible symptom, but the root problem is structural governance.

  • B. Correct.

    This is correct. The primary issue is the lack of a defined information security management structure. The CISO should first establish a formal governance model that clarifies roles and responsibilities, reporting relationships, decision-making authority, escalation paths, and the relationship between central security and distributed business or regional teams. This creates the foundation for consistent policy, risk ownership, accountability, and later operational improvements such as SOC centralization or control standardization.

  • C. Incorrect.

    This is incorrect because it overcorrects toward decentralization and weakens enterprise-wide governance. Regional tailoring may be appropriate within defined boundaries, but security ownership cannot be delegated entirely to business units without central standards, oversight, and risk governance. This option reflects a common misconception that agility requires abandoning centralized governance. In practice, effective structures balance enterprise oversight with local execution.

  • D. Incorrect.

    This is incorrect because internal audit should remain independent and provide assurance, not manage or enforce operational security responsibilities. Assigning audit an enforcement role compromises segregation of duties and undermines audit independence. Some candidates may select this because audit is associated with compliance, but governance and management accountability belong to executive leadership and line management, not the third line of defense.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam