712-50 exam dumps

712-50 practice question 97 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 97

Single answerLeading at Scale and Scope

A newly appointed CISO at a global manufacturing company must lead security across 18 business units operating in different regions, each with its own IT leadership, regulatory obligations, and budget authority. Recent internal audit findings show inconsistent control implementation, duplicated security tooling, and conflicting risk reporting to the board. The CEO has asked the CISO to improve enterprise-wide security outcomes without disrupting local business agility. Which action should the CISO take FIRST to lead effectively at scale and scope?

  1. A

    Mandate a single global security toolset and control baseline for all business units within the next quarter, regardless of local business or regulatory differences

  2. B

    Establish an enterprise security governance model with defined decision rights, a federated operating structure, and standardized risk reporting tied to business objectives

  3. C

    Delegate all security decisions to regional CISOs so each business unit can tailor controls independently and respond faster to local threats

  4. D

    Prioritize replacing underperforming security managers in business units with centrally appointed leaders before making governance changes

Show answer and explanation

Correct answer: B

Explanation

The best first step is to establish an enterprise security governance model with clear decision rights, a federated operating structure, and standardized risk reporting. In large, complex organizations, the CISO must lead through influence, structure, and alignment rather than relying primarily on tool mandates or local autonomy. A federated model is particularly effective when business units have legitimate differences in regulatory obligations, risk exposure, and operating models. It allows central leadership to set strategy, policy, risk appetite, and minimum expectations while permitting tailored implementation where needed.

This approach is consistent with widely accepted governance and security leadership practices reflected in frameworks such as COBIT, NIST CSF, and ISO/IEC 27001. These emphasize governance, accountability, risk-based decision-making, and consistent reporting as foundations for an effective security program. For a CCISO-level leader, the issue is not simply choosing controls or tools; it is creating the organizational mechanisms that enable consistent security outcomes across diverse environments. Once governance is in place, the CISO is better positioned to rationalize tooling, harmonize control baselines, define exception processes, and measure performance in a way the board and executive leadership can trust.

  • A. Incorrect.

    This is incorrect because immediately mandating a single toolset and uniform baseline across all business units may ignore legal, operational, and business-specific requirements. While standardization can reduce complexity and cost, doing it first without governance, decision rights, and risk alignment often creates resistance and can undermine business agility. This option reflects a common misconception that technology consolidation alone solves enterprise-scale leadership problems.

  • B. Correct.

    This is correct because leading at scale requires the CISO to create a governance structure that aligns enterprise objectives with local execution. A federated model allows central direction on strategy, policies, risk appetite, and reporting, while preserving flexibility for regional or business-unit implementation where justified. Standardized risk reporting also enables the board to receive consistent, decision-useful information. Defining decision rights is a foundational leadership step because it clarifies who owns strategy, exceptions, funding priorities, and accountability across a complex organization.

  • C. Incorrect.

    This is incorrect because fully decentralizing security decisions increases the likelihood of further inconsistency, duplicated spending, and fragmented risk management. Local responsiveness is important, but without enterprise governance and common reporting, the organization will struggle to manage aggregate risk or demonstrate consistent oversight to executives and the board. Candidates may choose this option if they overemphasize agility while underestimating the need for enterprise coordination.

  • D. Incorrect.

    This is incorrect because personnel changes may be necessary in some cases, but replacing leaders before establishing the target operating model addresses symptoms rather than root causes. Inconsistent outcomes across business units often stem from unclear governance, conflicting priorities, and lack of defined accountability rather than individual performance alone. Effective executive leadership at scale begins with structure, mandate, and alignment before major organizational reshuffling.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam