CCISO Security Program Development & Management 2 — Questions and Answers
Question 1: A CISO is tasked with establishing security metrics for the board. Which metric BEST demonstrates the business value of the security program?
- Number of vulnerabilities patched per quarter
- Reduction in mean time to detect (MTTD) and respond (MTTR) to incidents (Correct answer)
- Total number of security policies in place
- Count of security awareness training completions
Correct answer: Reduction in mean time to detect (MTTD) and respond (MTTR) to incidents
MTTD and MTTR directly tie security operational efficiency to business risk reduction, making them meaningful to board-level stakeholders.
Question 2: When developing a security program charter, which element is MOST critical to include to ensure executive sponsorship?
- Detailed technical architecture diagrams
- Defined authority, scope, and accountability of the security function (Correct answer)
- List of all security tools and vendors
- Specific vulnerability remediation timelines
Correct answer: Defined authority, scope, and accountability of the security function
A charter must define authority and scope so that executives understand and formally delegate responsibility to the CISO.
Question 3: A security program is failing to align with business objectives. What is the FIRST step a CISO should take to remediate this?
- Hire additional security staff
- Conduct a stakeholder analysis to understand business priorities (Correct answer)
- Increase the security budget request
- Implement additional security controls
Correct answer: Conduct a stakeholder analysis to understand business priorities
Understanding stakeholder priorities is the foundation for aligning security investments with the business objectives that matter most.
Question 4: Which approach BEST describes integrating security into an organization's SDLC?
- Performing penetration testing only before production releases
- Embedding security requirements, reviews, and testing at every phase of development (Correct answer)
- Requiring developers to pass a security certification
- Installing WAFs in front of all applications
Correct answer: Embedding security requirements, reviews, and testing at every phase of development
A DevSecOps approach embeds security throughout all SDLC phases rather than treating it as a gate at the end.
Question 5: A CISO must justify a security budget increase to the CFO. Which financial model is MOST effective?
- Total cost of ownership (TCO) analysis of security tools
- Return on security investment (ROSI) tied to risk reduction (Correct answer)
- Comparison of competitor security spending
- Five-year capital expenditure projection
Correct answer: Return on security investment (ROSI) tied to risk reduction
ROSI frames security spending in terms of quantified risk reduction, which is the language most compelling to financial executives.
Question 6: What is the PRIMARY purpose of a security program roadmap?
- To document all current security incidents
- To provide a prioritized, time-bound plan for maturing security capabilities (Correct answer)
- To list all compliance requirements the organization must meet
- To assign blame for past security failures
Correct answer: To provide a prioritized, time-bound plan for maturing security capabilities
A roadmap gives leadership a clear view of where the program is headed, what capabilities will be built, and when.
Question 7: Which governance structure BEST supports enterprise-wide security program accountability?
- A single CISO with no formal committee structure
- A security steering committee with cross-functional representation (Correct answer)
- Delegating all security decisions to IT management
- Outsourcing security governance to a managed service provider
Correct answer: A security steering committee with cross-functional representation
A cross-functional steering committee ensures security decisions reflect business, legal, HR, and operational perspectives and shares accountability.
A CISO is tasked with establishing security metrics for the board.
Which metric BEST demonstrates the business value of the security program?