712-50 Question 94
Single answerFunding Request Justification and ROI PromotionA newly appointed CISO is requesting funding for a data loss prevention (DLP) program after several near-miss incidents involving sensitive customer data. The CFO is skeptical because the organization has not experienced a publicly reported breach and wants a business case that goes beyond fear, uncertainty, and doubt. The CISO must justify the investment in terms executives will support and show how value will be measured after approval. Which approach is the MOST effective for justifying the funding request and promoting ROI?
- A
Present the request primarily as a compliance necessity, emphasizing that security controls should be funded whenever regulations might apply, even if financial benefits are difficult to quantify.
- B
Build a business case that estimates current exposure using probable loss scenarios, maps the DLP program to reduction in risk and operational inefficiencies, and defines post-implementation metrics such as reduced incident handling time, fewer policy violations, and lower expected loss.
- C
Justify the funding by comparing the proposed DLP budget to the average cost of a major breach reported in industry surveys and asserting that any preventive spending below that figure represents positive ROI.
- D
Focus the proposal on technical superiority, showing that the DLP platform has more features than competing products and that stronger technology alone demonstrates sufficient return to the business.
Show answer and explanation
Correct answer: B
Explanation
For CCISO-level decision making, funding requests should be framed in business terms: risk reduction, expected loss avoidance, operational efficiency, strategic alignment, and measurable performance indicators. A CISO should avoid relying solely on technical language, generalized breach headlines, or compliance pressure unless those factors are directly tied to enterprise impact. A more credible approach is to quantify probable loss exposure using realistic scenarios, then show how the proposed control reduces either likelihood, impact, or response cost. Where direct ROI is difficult to calculate, security leaders commonly use risk-adjusted justification supported by key risk indicators (KRIs) and key performance indicators (KPIs). This aligns with broadly accepted practices from governance and risk management frameworks such as NIST guidance on risk assessment and FAIR-style financial risk analysis concepts, as well as executive budgeting expectations that capital requests include measurable benefits and accountability after implementation.
- A. Incorrect.
This is not the most effective approach. Compliance can be a valid component of a funding request, especially if there are clear regulatory obligations or audit findings. However, leading with compliance alone often produces a weak business case because it may not connect the investment to enterprise risk reduction, operational improvement, or measurable financial outcomes. Executives typically expect security leaders to translate control needs into business impact rather than rely only on regulatory pressure.
- B. Correct.
This is the best answer. A strong executive-level justification ties the investment to business risk, likelihood and impact of loss scenarios, and measurable outcomes after implementation. For a DLP program, this means estimating the current exposure from insider error, data handling weaknesses, and downstream costs such as investigations, legal review, customer notification, and business disruption. It also means identifying operational benefits, such as reduced manual monitoring effort, faster triage, and fewer policy exceptions. Defining outcome metrics beforehand supports ROI promotion because the CISO can later demonstrate whether the investment reduced expected loss or improved process efficiency.
- C. Incorrect.
This is a common but flawed justification. Industry breach cost averages can provide supporting context, but they are not enough to establish ROI for a specific organization. Average breach figures may not reflect the company's data types, control maturity, threat profile, loss history, or probable event frequency. Using generic external numbers without organization-specific analysis can undermine credibility with a CFO who expects a tailored financial rationale.
- D. Incorrect.
This is incorrect because feature depth does not equate to business value. A technically impressive product may still be a poor investment if it does not address the organization's highest-priority risks, integrate with existing processes, or produce measurable improvements. Senior executives fund outcomes, not feature lists. Technology selection should follow the business case, not replace it.