CCISO Strategic Planning 5 — Questions and Answers
Question 1: A CISO is preparing a 5-year security strategy immediately following a major data breach. Which element should receive HIGHEST priority in the early phases?
- Long-term technology procurement planning
- Immediate capability gaps in detection and response exposed by the breach (Correct answer)
- Restructuring the entire security organization
- Renegotiating all vendor contracts
Correct answer: Immediate capability gaps in detection and response exposed by the breach
Post-breach strategic planning must first address the specific capability failures exposed by the incident before focusing on longer-term transformation.
Question 2: Which planning technique helps a CISO identify which security initiatives are time-sensitive versus those that can be sequenced later?
- Business impact analysis (BIA)
- Critical path method (CPM) (Correct answer)
- Vulnerability severity scoring (CVSS)
- Risk heat map generation
Correct answer: Critical path method (CPM)
Critical path method identifies the sequence of dependent tasks that determine the minimum time to complete a strategic initiative.
Question 3: In strategic planning, which output BEST communicates the security program's current status and forward trajectory to board-level stakeholders?
- Detailed firewall audit logs
- An executive security dashboard with KPIs, KRIs, and roadmap milestones (Correct answer)
- A full network vulnerability report
- Monthly patch management status emails
Correct answer: An executive security dashboard with KPIs, KRIs, and roadmap milestones
Executive dashboards summarize program health through key performance and risk indicators at a level appropriate for board-level decision-making.
Question 4: When a CISO develops security strategy for an organization operating in a heavily regulated industry, regulatory compliance requirements should be treated as:
- The sole driver of the security strategy
- A baseline constraint, with risk-driven priorities built above that floor (Correct answer)
- Optional guidelines subject to cost-benefit analysis
- Responsibility of the legal department, not the CISO
Correct answer: A baseline constraint, with risk-driven priorities built above that floor
Compliance sets a minimum required baseline; effective security strategy layers risk-driven controls above that floor to address actual threats.
Question 5: A CISO incorporates lessons learned from peer organizations' breaches into the strategic plan. This practice is an example of:
- Competitive intelligence gathering
- Cyber threat intelligence integration into strategic planning (Correct answer)
- Benchmarking operational metrics
- Supply chain risk management
Correct answer: Cyber threat intelligence integration into strategic planning
Using external breach intelligence to inform strategic decisions is a core application of cyber threat intelligence at the strategic planning level.
Question 6: Which scenario BEST illustrates misalignment between security strategy and business strategy?
- Security budget increases alongside revenue growth
- The security team blocks a merger due to undisclosed cyber risks (Correct answer)
- A CISO hires staff to support a planned cloud migration
- Security KPIs are reported in quarterly business reviews
Correct answer: The security team blocks a merger due to undisclosed cyber risks
If security risks from a merger are not surfaced until they cause a blockage, the security program is reactive rather than integrated with business strategy.
Question 7: A CISO wants to quantify the financial return of security controls to justify budget increases. The MOST appropriate method is:
- CVSS scoring of identified vulnerabilities
- Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy (Correct answer)
- Number of security incidents closed per quarter
- Headcount ratio of security staff to total employees
Correct answer: Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy
ROSI calculates expected loss reduction against control cost, providing a financial justification framework for security investment decisions.
A CISO is preparing a 5-year security strategy immediately following a major data breach.
Which element should receive HIGHEST priority in the early phases?