CCISO Security Program Development & Management 3 — Questions and Answers
Question 1: A CISO is evaluating the maturity of the security program using CMMI. The organization consistently follows defined, documented processes but does not yet measure process effectiveness. Which maturity level does this represent?
- Level 1 – Initial
- Level 2 – Managed
- Level 3 – Defined (Correct answer)
- Level 4 – Quantitatively Managed
Correct answer: Level 3 – Defined
CMMI Level 3 (Defined) means processes are standardized and documented organization-wide, but measurement and control come at Level 4.
Question 2: Which element distinguishes a strategic security plan from an operational security plan?
- A strategic plan focuses on day-to-day incident response procedures
- A strategic plan defines long-term security goals aligned with business direction (Correct answer)
- An operational plan sets the three-to-five-year vision for the security program
- A strategic plan details specific technical control configurations
Correct answer: A strategic plan defines long-term security goals aligned with business direction
Strategic plans address long-term direction and alignment with the business, while operational plans handle near-term execution and day-to-day activities.
Question 3: An organization wants to benchmark its security program against industry peers. Which framework is BEST suited for this purpose?
- NIST SP 800-53
- COBIT 2019
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF was designed specifically for benchmarking and communicating cybersecurity posture across industries using its tiered maturity model.
Question 4: A CISO discovers that a third-party vendor has access to sensitive customer data but has not been assessed for security compliance. What is the MOST appropriate immediate action?
- Terminate the vendor relationship immediately
- Conduct a vendor risk assessment and enforce contractual security requirements (Correct answer)
- Notify customers of the potential exposure
- Restrict all vendor access until a full audit is completed
Correct answer: Conduct a vendor risk assessment and enforce contractual security requirements
Conducting a risk assessment and enforcing contractual requirements is the measured, governance-based response before escalating to more disruptive actions.
Question 5: Which of the following is the BEST indicator that a security awareness program is effective?
- High attendance rates at mandatory training sessions
- Measurable reduction in employees clicking phishing simulation links over time (Correct answer)
- Number of security policies employees have acknowledged
- Volume of security newsletters distributed
Correct answer: Measurable reduction in employees clicking phishing simulation links over time
Behavioral change, such as declining phishing click rates, is the best evidence that training is actually changing employee behavior and reducing risk.
Question 6: When building a security program in a decentralized organization, what is the MOST effective model for maintaining consistent security standards?
- Fully centralized security team that controls all decisions
- Federated model with central policy and local implementation accountability (Correct answer)
- Each business unit independently defines its own security standards
- Outsourcing all security responsibilities to a single MSSP
Correct answer: Federated model with central policy and local implementation accountability
A federated model balances central policy consistency with local flexibility, which is essential in organizations with autonomous business units.
Question 7: A CISO is developing KPIs for the security program. Which KPI is MOST aligned with measuring program effectiveness rather than program activity?
- Number of security patches applied monthly
- Percentage of critical assets with up-to-date risk assessments (Correct answer)
- Number of security team training hours completed
- Count of security policies reviewed annually
Correct answer: Percentage of critical assets with up-to-date risk assessments
Coverage of risk assessments on critical assets measures whether the program is actually managing risk, not just performing activities.
A CISO is evaluating the maturity of the security program using CMMI.
The organization consistently follows defined, documented processes but does not yet measure process effectiveness.
Which maturity level does this represent?