CCISO Security Program Development & Management 5 — Questions and Answers
Question 1: A CISO is asked to reduce the security budget by 20%. Which approach BEST demonstrates risk-informed decision-making?
- Eliminate all red team activities as a non-essential luxury
- Map proposed cuts to their risk impact and present the analysis to leadership (Correct answer)
- Reduce headcount equally across all security teams
- Cancel all vendor contracts and rely on open-source tools
Correct answer: Map proposed cuts to their risk impact and present the analysis to leadership
Mapping cuts to risk impact ensures leadership understands the consequences and makes an informed decision rather than the CISO absorbing the risk silently.
Question 2: Which of the following BEST describes the concept of 'security by design' in program management?
- Designing secure physical office spaces for the security team
- Incorporating security requirements and controls into systems from their initial design phase (Correct answer)
- Installing security cameras throughout corporate facilities
- Designing a security awareness curriculum
Correct answer: Incorporating security requirements and controls into systems from their initial design phase
Security by design means embedding security considerations from the earliest stages of system design rather than adding them after development.
Question 3: A CISO is implementing a security program for a recently acquired company. What is the MOST critical first step in integration?
- Immediately replacing all of the acquired company's security tools
- Conducting a gap assessment comparing the acquired company's controls to parent company standards (Correct answer)
- Requiring the acquired company to achieve ISO 27001 certification within 90 days
- Deploying the parent company's security agents on all acquired systems immediately
Correct answer: Conducting a gap assessment comparing the acquired company's controls to parent company standards
A gap assessment reveals where the acquired company's security posture deviates from standards, enabling a risk-prioritized integration roadmap.
Question 4: What is the PRIMARY benefit of implementing a formal exception management process within a security program?
- It allows the security team to ignore policy violations
- It provides a documented, risk-accepted path for business units that cannot immediately comply with policy (Correct answer)
- It reduces the number of security policies needed
- It transfers liability for security incidents to business units
Correct answer: It provides a documented, risk-accepted path for business units that cannot immediately comply with policy
Exception management balances business agility with risk governance by formally documenting, approving, and tracking deviations from security policy.
Question 5: An organization's security program lacks integration with its enterprise risk management (ERM) framework. Which outcome is MOST likely?
- The security team will be more agile and responsive to threats
- Security risks will not be properly prioritized or reported alongside other enterprise risks (Correct answer)
- The ERM framework will become more effective without security inputs
- Compliance costs will decrease significantly
Correct answer: Security risks will not be properly prioritized or reported alongside other enterprise risks
Without ERM integration, security risks are managed in isolation and may be under-resourced or misaligned with the organization's overall risk appetite.
Question 6: A CISO wants to assess whether security controls are operating effectively, not just whether they exist. Which activity BEST accomplishes this?
- Reviewing the security policy documentation library
- Conducting control effectiveness testing through audits and red team exercises (Correct answer)
- Verifying that all controls are listed in the risk register
- Checking vendor compliance certifications
Correct answer: Conducting control effectiveness testing through audits and red team exercises
Control effectiveness testing, including audits and adversarial simulations, validates that controls work as intended under real conditions.
Question 7: Which metric BEST measures the effectiveness of a vulnerability management program within a security program?
- Total number of vulnerability scans conducted per month
- Mean time to remediate (MTTR) critical vulnerabilities within defined SLA targets (Correct answer)
- Number of vulnerability management staff employed
- Total count of open vulnerabilities in the scanner
Correct answer: Mean time to remediate (MTTR) critical vulnerabilities within defined SLA targets
MTTR against defined SLAs measures whether the program is actually closing risk in a timely manner, not just discovering vulnerabilities.
A CISO is asked to reduce the security budget by 20%.
Which approach BEST demonstrates risk-informed decision-making?