CCISO Strategic Planning 3 β Questions and Answers
Question 1: A CISO uses Porter's Five Forces model during strategic planning. Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?
- Threat of new entrants
- Bargaining power of suppliers
- Threat of substitute products (Correct answer)
- Rivalry among existing competitors
Correct answer: Threat of substitute products
The threat of substitutes captures the risk that alternative technologies or approaches could render current security tools obsolete.
Question 2: In strategic planning, 'capability maturity' assessments help a CISO to:
- Identify specific exploited vulnerabilities
- Benchmark current security practices against a defined scale to prioritize improvements (Correct answer)
- Satisfy annual audit requirements
- Certify staff competency levels
Correct answer: Benchmark current security practices against a defined scale to prioritize improvements
Capability maturity models (e.g., CMM, C2M2) measure process maturity on a defined scale and guide investment in areas needing improvement.
Question 3: Which document typically serves as the top-level policy artifact that gives the CISO authority to enforce the security strategy?
- Business continuity plan
- Information security charter (Correct answer)
- Incident response plan
- Network security standard
Correct answer: Information security charter
An information security charter (or policy) establishes executive-level mandate for security governance and the CISO's authority.
Question 4: When prioritizing strategic security initiatives, a CISO should PRIMARILY consider:
- Vendor recommendations and product roadmaps
- Risk reduction value relative to business impact and available resources (Correct answer)
- Regulatory penalties alone
- Industry peers' technology choices
Correct answer: Risk reduction value relative to business impact and available resources
Initiative prioritization must weigh risk reduction potential against business impact and resource constraints for maximum strategic value.
Question 5: A gap analysis in security strategic planning compares which two states?
- Attacker capabilities vs. defender capabilities
- Current security posture vs. desired future-state security posture (Correct answer)
- Budgeted spend vs. actual spend
- Compliance status vs. regulatory requirements
Correct answer: Current security posture vs. desired future-state security posture
A gap analysis identifies the delta between where the organization is today and where it needs to be to meet strategic security objectives.
Question 6: Which of the following BEST describes a security strategy's 'strategic objective'?
- A specific technical control to be implemented within 30 days
- A broad, measurable outcome the security program aims to achieve over the planning period (Correct answer)
- An SLA metric in a vendor contract
- A password complexity requirement in a security policy
Correct answer: A broad, measurable outcome the security program aims to achieve over the planning period
Strategic objectives are high-level, measurable outcomes (e.g., 'achieve ISO 27001 certification within 2 years') that guide program direction.
Question 7: A CISO presents a security strategy to the board but receives pushback that it conflicts with a planned acquisition. This scenario highlights the importance of:
- Annual penetration testing
- Integrating security strategy into enterprise strategic planning cycles (Correct answer)
- Stricter access control policies
- Increasing the security budget
Correct answer: Integrating security strategy into enterprise strategic planning cycles
Security strategy must be synchronized with enterprise planning cycles so that major business events like acquisitions are considered from the outset.
A CISO uses Porter's Five Forces model during strategic planning.
Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?