← All CCISO Flashcard Decks

Strategic Planning Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Strategic Planning flashcards as text
  1. When conducting a SWOT analysis for information security strategy, which quadrant specifically examines internal deficiencies that could hinder security objectives?

    Answer: Weaknesses

    Weaknesses represent internal deficiencies such as skill gaps, legacy systems, or budget constraints that can undermine security goals.

  2. A CISO is tasked with aligning the security roadmap to a 3-year business transformation. Which planning horizon best describes this effort?

    Answer: Strategic planning

    Strategic planning addresses long-term goals (typically 3–5 years) and aligns security initiatives with overall business direction.

  3. Which framework is most commonly used to cascade high-level security strategy into measurable departmental objectives?

    Answer: Balanced Scorecard

    The Balanced Scorecard translates strategic vision into four perspectives—financial, customer, internal process, and learning—with linked KPIs.

  4. During strategic planning, a CISO identifies that a proposed cloud migration increases residual risk beyond the board's appetite. The BEST response is to:

    Answer: Escalate findings and propose risk treatment options to leadership

    The CISO should surface findings to decision-makers and present treatment options so leadership can make informed risk-acceptance decisions.

  5. What does the term 'security architecture roadmap' primarily define in strategic planning?

    Answer: A prioritized sequence of security initiatives aligned to future-state objectives

    A security architecture roadmap outlines the phased progression from the current security state to the desired future state.

  6. Which metric type directly demonstrates the business value of security investments to executive stakeholders?

    Answer: Cost avoidance from prevented incidents

    Cost avoidance metrics translate security activities into financial terms that resonate with business leadership and justify investment.

  7. A CISO reviewing a strategic plan notices security goals are not linked to any business outcomes. This represents a failure of:

    Answer: Business-IT alignment

    Business-IT alignment ensures security objectives directly support and are traceable to organizational business outcomes and priorities.