712-50 Question 99
Single answerOrganizational Change LeadershipA newly appointed CISO is leading a global initiative to implement stronger identity and access management controls, including mandatory MFA and tighter privileged access reviews. The program has strong board support, but several business unit leaders are resisting because they believe the changes will slow operations and increase help desk costs. Pilot results show the controls reduce account takeover incidents, but user adoption is inconsistent across regions. To improve adoption without losing executive momentum, what should the CISO do FIRST?
- A
Issue a policy directive requiring immediate enterprise-wide adoption and escalate noncompliant business leaders to the board
- B
Engage business unit leaders and regional stakeholders to identify operational concerns, tailor the rollout plan, and communicate measurable business risk reduction from the pilot
- C
Delay the program until the organization completes a full technology refresh so the controls can be deployed uniformly
- D
Delegate implementation entirely to IT operations because resistance is primarily a technical deployment issue
Show answer and explanation
Correct answer: B
Explanation
The most appropriate first action is to strengthen stakeholder engagement and change adoption efforts while reinforcing the business value of the security initiative. In CCISO-level leadership, organizational change is not achieved solely through policy mandates or technical implementation; it requires executive influence, stakeholder alignment, communication, and management of business impact. Established change management principles, such as those reflected in Kotter's change model and ADKAR-style adoption practices, emphasize creating buy-in, addressing barriers, and sustaining momentum through visible wins and clear communication. From a security governance perspective, this also aligns with common best practices in frameworks such as NIST Cybersecurity Framework and COBIT, which stress that security outcomes depend on governance, communication, and integration with business processes. The board's support provides sponsorship, but the CISO must translate that support into business-level adoption by engaging leaders, using pilot data to demonstrate reduced account takeover risk, and adapting implementation to regional realities.
- A. Incorrect.
This is not the best first step. While executive sponsorship and policy enforcement are important, using authority alone at the outset often increases resistance and undermines long-term adoption. In organizational change leadership, especially for enterprise security transformations, leaders should first build stakeholder alignment, address local business impacts, and use evidence from pilots to create buy-in before escalating enforcement.
- B. Correct.
This is the best answer. Effective organizational change leadership requires stakeholder engagement, clear communication of the business case, and adaptation of implementation plans to operational realities. Since the board already supports the initiative and the pilot has demonstrated measurable risk reduction, the CISO should use that data to align business leaders, address regional adoption barriers, and shape a practical rollout. This approach supports sustainable change, not just technical deployment.
- C. Incorrect.
This is incorrect because it introduces unnecessary delay and shifts focus away from change leadership. The scenario already indicates the controls work in pilot and that the challenge is resistance and adoption, not lack of technical feasibility. Waiting for a full technology refresh would likely prolong exposure to known identity-related risks and reduce program momentum.
- D. Incorrect.
This is incorrect because the issue is not purely technical. The scenario describes business resistance, concerns about workflow impact, and inconsistent regional adoption, all of which are classic change management and leadership challenges. Delegating the matter entirely to IT operations ignores the CISO's responsibility to lead cross-functional transformation, influence executives, and manage organizational adoption.