712-50 Question 91
Single answerLeading Organization (6 questions)A newly appointed CISO at a multinational manufacturing company is trying to improve the security culture across business units that have historically viewed cybersecurity as an IT problem. The CEO supports the CISO's mandate, but several plant managers resist new controls because they fear production delays and revenue impact. The board has asked the CISO to lead an organizational change effort that improves accountability without creating unnecessary conflict. Which action should the CISO take FIRST to most effectively lead the organization toward sustained security ownership?
- A
Mandate immediate enforcement of all corporate security standards across every plant and report noncompliance directly to the board
- B
Work with executive leadership and business unit heads to define risk-based security objectives, assign accountable owners, and align performance measures with business outcomes
- C
Launch a companywide phishing awareness campaign to demonstrate quick wins and improve employee participation in security
- D
Transfer security decision-making authority from plant managers to the central security team so controls can be implemented consistently
Show answer and explanation
Correct answer: B
Explanation
In CCISO's Leading Organization domain, the emphasis is on executive leadership, influencing organizational culture, aligning security with business strategy, and establishing accountability structures that drive sustained behavior change. In this scenario, the CISO's first priority is not technical enforcement or awareness training, but stakeholder alignment and governance design. Best practices from security and governance frameworks such as NIST Cybersecurity Framework governance concepts, ISO/IEC 27001 leadership and organizational roles, and COBIT's governance-accountability principles support defining roles, risk ownership, objectives, and measurement mechanisms in business terms. The most effective leaders create shared accountability with business executives, use risk-based prioritization, and align incentives and performance expectations to organizational outcomes. That makes option 2 the best answer.
- A. Incorrect.
This is not the best first action. Although board reporting and enforcement have a role in governance, immediately mandating all standards without first building executive alignment, defining accountability, and considering operational realities is likely to increase resistance. In a leading-organization context, the CISO should first create shared ownership and a risk-informed governance model rather than rely primarily on top-down escalation.
- B. Correct.
This is correct. Leading the organization effectively requires the CISO to translate security into business terms, align stakeholders, and establish accountability at the appropriate management levels. By partnering with executive leadership and business unit heads, the CISO can define risk-based objectives, assign ownership, and integrate security expectations into management processes and performance measures. This approach supports long-term cultural change, reduces adversarial dynamics, and is consistent with executive leadership responsibilities expected of a CCISO.
- C. Incorrect.
This is a useful supporting activity but not the best first step for the scenario. Awareness campaigns can improve general participation, but the core problem described is leadership resistance, competing business priorities, and lack of ownership among plant managers. Culture change at this level starts with governance, accountability, and executive alignment rather than with an isolated end-user awareness initiative.
- D. Incorrect.
This is plausible because centralization can improve consistency, but it is not the most effective first move for sustained organizational leadership. Removing decision-making authority from business leaders may weaken accountability, create further resistance, and disconnect security from operational realities. Mature security leadership generally embeds risk ownership with the business while the security function provides governance, standards, advisory support, and oversight.