CCISO Security Program Development & Management 4 — Questions and Answers
Question 1: A newly appointed CISO finds the security program is reactive with no formal strategy. What should be the FIRST priority?
- Deploy a SIEM solution to improve visibility
- Conduct a comprehensive risk assessment to establish a baseline (Correct answer)
- Create a security awareness program for all employees
- Hire additional penetration testers
Correct answer: Conduct a comprehensive risk assessment to establish a baseline
A risk assessment establishes the current state and priorities, forming the foundation for any strategic security program development.
Question 2: Which document BEST communicates the organization's commitment to information security to both internal and external stakeholders?
- System Security Plan (SSP)
- Information Security Policy (Correct answer)
- Business Continuity Plan (BCP)
- Risk Register
Correct answer: Information Security Policy
An Information Security Policy is the high-level governance document that formally declares the organization's commitment and sets the tone from leadership.
Question 3: An organization is expanding globally and must manage security across multiple regulatory jurisdictions. What is the MOST effective approach?
- Apply the strictest single jurisdiction's requirements globally
- Develop a baseline security framework and layer jurisdiction-specific controls on top (Correct answer)
- Create entirely separate security programs for each country
- Rely on local legal counsel to manage all compliance requirements
Correct answer: Develop a baseline security framework and layer jurisdiction-specific controls on top
A baseline with layered jurisdiction-specific controls efficiently meets multiple regulatory requirements without duplicating the entire security program.
Question 4: Which role in an information security governance structure is PRIMARILY responsible for accepting residual risk?
- CISO
- Risk Manager
- Business Process Owner / Senior Management (Correct answer)
- Internal Auditor
Correct answer: Business Process Owner / Senior Management
Risk acceptance is a business decision made by business process owners or senior management who understand the risk appetite and business impact.
Question 5: A CISO wants to ensure security requirements are captured for a new cloud migration project from the start. Which practice BEST achieves this?
- Conducting a security review after the migration is complete
- Requiring security sign-off only on the final architecture design
- Participating in project initiation and including security in the business case (Correct answer)
- Performing a penetration test on the cloud environment post-migration
Correct answer: Participating in project initiation and including security in the business case
Integrating security at project initiation ensures requirements are built in by design rather than retrofitted, reducing cost and risk.
Question 6: When presenting the security program's annual report to the board, which content is MOST important to include?
- Detailed firewall rule sets and network diagrams
- Risk posture trends, program accomplishments, and resource gaps tied to business risk (Correct answer)
- Complete list of all CVEs patched during the year
- Technical specifications of all security tools deployed
Correct answer: Risk posture trends, program accomplishments, and resource gaps tied to business risk
Boards need risk posture trends and business-relevant gaps, not technical details, to make informed decisions about security investment.
Question 7: A CISO is building a security operations capability. Which factor MOST impacts the decision between building an in-house SOC versus using a managed SOC (MSSP)?
- Availability of specific security certifications among staff
- Cost, required expertise level, and need for customized detection for the business (Correct answer)
- Preference of the IT director
- Number of existing security tools already deployed
Correct answer: Cost, required expertise level, and need for customized detection for the business
The build-vs-buy decision for a SOC is primarily driven by cost, the specialized expertise required, and whether detection needs are generic or highly customized.
A newly appointed CISO finds the security program is reactive with no formal strategy.
What should be the FIRST priority?