โ† All CCISO Flashcard Decks

Strategic Planning Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Strategic Planning flashcards as text
  1. A CISO uses Porter's Five Forces model during strategic planning. Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?

    Answer: Threat of substitute products

    The threat of substitutes captures the risk that alternative technologies or approaches could render current security tools obsolete.

  2. In strategic planning, 'capability maturity' assessments help a CISO to:

    Answer: Benchmark current security practices against a defined scale to prioritize improvements

    Capability maturity models (e.g., CMM, C2M2) measure process maturity on a defined scale and guide investment in areas needing improvement.

  3. Which document typically serves as the top-level policy artifact that gives the CISO authority to enforce the security strategy?

    Answer: Information security charter

    An information security charter (or policy) establishes executive-level mandate for security governance and the CISO's authority.

  4. When prioritizing strategic security initiatives, a CISO should PRIMARILY consider:

    Answer: Risk reduction value relative to business impact and available resources

    Initiative prioritization must weigh risk reduction potential against business impact and resource constraints for maximum strategic value.

  5. A gap analysis in security strategic planning compares which two states?

    Answer: Current security posture vs. desired future-state security posture

    A gap analysis identifies the delta between where the organization is today and where it needs to be to meet strategic security objectives.

  6. Which of the following BEST describes a security strategy's 'strategic objective'?

    Answer: A broad, measurable outcome the security program aims to achieve over the planning period

    Strategic objectives are high-level, measurable outcomes (e.g., 'achieve ISO 27001 certification within 2 years') that guide program direction.

  7. A CISO presents a security strategy to the board but receives pushback that it conflicts with a planned acquisition. This scenario highlights the importance of:

    Answer: Integrating security strategy into enterprise strategic planning cycles

    Security strategy must be synchronized with enterprise planning cycles so that major business events like acquisitions are considered from the outset.