CCISO Strategic Planning 2 — Questions and Answers
Question 1: When conducting a SWOT analysis for information security strategy, which quadrant specifically examines internal deficiencies that could hinder security objectives?
- Strengths
- Weaknesses (Correct answer)
- Threats
- Opportunities
Correct answer: Weaknesses
Weaknesses represent internal deficiencies such as skill gaps, legacy systems, or budget constraints that can undermine security goals.
Question 2: A CISO is tasked with aligning the security roadmap to a 3-year business transformation. Which planning horizon best describes this effort?
- Operational planning
- Tactical planning
- Strategic planning (Correct answer)
- Contingency planning
Correct answer: Strategic planning
Strategic planning addresses long-term goals (typically 3–5 years) and aligns security initiatives with overall business direction.
Question 3: Which framework is most commonly used to cascade high-level security strategy into measurable departmental objectives?
- COBIT 2019
- Balanced Scorecard (Correct answer)
- ISO 27001 Annex A
- NIST RMF
Correct answer: Balanced Scorecard
The Balanced Scorecard translates strategic vision into four perspectives—financial, customer, internal process, and learning—with linked KPIs.
Question 4: During strategic planning, a CISO identifies that a proposed cloud migration increases residual risk beyond the board's appetite. The BEST response is to:
- Halt the migration indefinitely
- Escalate findings and propose risk treatment options to leadership (Correct answer)
- Accept the risk without disclosure
- Transfer all risk to the cloud provider
Correct answer: Escalate findings and propose risk treatment options to leadership
The CISO should surface findings to decision-makers and present treatment options so leadership can make informed risk-acceptance decisions.
Question 5: What does the term 'security architecture roadmap' primarily define in strategic planning?
- Network topology diagrams for current infrastructure
- A prioritized sequence of security initiatives aligned to future-state objectives (Correct answer)
- Incident response playbooks for known threat vectors
- Vendor contracts for security tools
Correct answer: A prioritized sequence of security initiatives aligned to future-state objectives
A security architecture roadmap outlines the phased progression from the current security state to the desired future state.
Question 6: Which metric type directly demonstrates the business value of security investments to executive stakeholders?
- Firewall rule count
- Patch compliance percentage
- Cost avoidance from prevented incidents (Correct answer)
- Number of vulnerability scans completed
Correct answer: Cost avoidance from prevented incidents
Cost avoidance metrics translate security activities into financial terms that resonate with business leadership and justify investment.
Question 7: A CISO reviewing a strategic plan notices security goals are not linked to any business outcomes. This represents a failure of:
- Vulnerability management
- Business-IT alignment (Correct answer)
- Incident classification
- Change management
Correct answer: Business-IT alignment
Business-IT alignment ensures security objectives directly support and are traceable to organizational business outcomes and priorities.
When conducting a SWOT analysis for information security strategy, which quadrant specifically examines internal deficiencies that could hinder security objectives?