CCISO Strategic Planning 4 β Questions and Answers
Question 1: Which governance structure BEST ensures security strategic decisions receive appropriate executive-level oversight?
- A weekly technical security team standup
- A security steering committee with C-suite and board representation (Correct answer)
- An internal audit department review
- A departmental IT risk committee
Correct answer: A security steering committee with C-suite and board representation
A security steering committee with executive and board members ensures strategic security decisions are vetted at the appropriate level of authority.
Question 2: In the context of CCISO strategic planning, 'strategic risk' is BEST defined as:
- Risks arising from day-to-day IT operations
- Risks that could prevent the organization from achieving its long-term business objectives (Correct answer)
- Regulatory fines for non-compliance
- Risks documented in the vulnerability scanner
Correct answer: Risks that could prevent the organization from achieving its long-term business objectives
Strategic risk refers to high-level uncertainties that threaten the organization's ability to execute its long-term strategy.
Question 3: A CISO adopts an 'assume breach' philosophy in strategic planning. This approach PRIMARILY affects which planning element?
- Perimeter defense investment levels
- Detection, response, and recovery capability investments (Correct answer)
- Physical security posture
- Employee background check frequency
Correct answer: Detection, response, and recovery capability investments
Assume breach shifts strategic focus from prevention-only to robust detection, response, and recovery, accepting that perimeter breaches will occur.
Question 4: When integrating cybersecurity into enterprise risk management (ERM), the CISO's role is to:
- Replace the Chief Risk Officer's responsibilities
- Translate cyber risks into business-impact terms understood by risk and finance executives (Correct answer)
- Manage only technical risks within the IT department
- Eliminate all residual cyber risk
Correct answer: Translate cyber risks into business-impact terms understood by risk and finance executives
The CISO bridges the gap between technical cyber risk and business risk language so that cyber risks are properly reflected in the ERM framework.
Question 5: Which approach ensures that security strategic planning remains relevant as the threat landscape evolves?
- Locking the strategy document and revisiting only every 5 years
- Embedding continuous threat intelligence review cycles into strategic planning (Correct answer)
- Outsourcing all strategic updates to a consulting firm
- Relying solely on compliance mandates to trigger strategy updates
Correct answer: Embedding continuous threat intelligence review cycles into strategic planning
Incorporating ongoing threat intelligence into planning cycles ensures the strategy adapts to emerging risks without waiting for a full planning refresh.
Question 6: A CISO's strategic plan includes a zero-trust network architecture initiative. Which business driver MOST likely justified this investment?
- Desire to reduce the number of security vendors
- Increasing remote work and cloud adoption that eroded traditional perimeter controls (Correct answer)
- Regulatory mandate requiring zero-trust specifically
- Budget surplus at the end of the fiscal year
Correct answer: Increasing remote work and cloud adoption that eroded traditional perimeter controls
Zero-trust architectures are primarily driven by the dissolution of network perimeters due to remote work, cloud services, and mobile devices.
Question 7: What is the primary purpose of a security program charter in strategic planning?
- To list all approved security vendors
- To formally establish scope, authority, accountability, and objectives of the security program (Correct answer)
- To serve as the annual security audit report
- To document network diagrams and asset inventories
Correct answer: To formally establish scope, authority, accountability, and objectives of the security program
A security program charter defines mandate, scope, roles, authorities, and goals, providing the foundational governance document for the program.
Which governance structure BEST ensures security strategic decisions receive appropriate executive-level oversight?