CSL CSL Cybersecurity Budget & Resource Allocation 1 — Questions and Answers
Question 1: Which financial metric helps a CSL leader justify cybersecurity investments to the board?
- Return on Security Investment (ROSI) quantifying risk reduction relative to cost (Correct answer)
- Gross profit margin
- Marketing spend percentage
- Employee turnover rate
Correct answer: Return on Security Investment (ROSI) quantifying risk reduction relative to cost
ROSI expresses cybersecurity investments in terms of risk reduction value, allowing business leaders to evaluate security spending using financial decision-making frameworks.
Question 2: What does the 'cost of a breach' model help cybersecurity leaders do?
- Quantify potential financial impact of incidents to justify preventive investment (Correct answer)
- Calculate IT help desk operating costs
- Measure software development productivity
- Forecast market share growth
Correct answer: Quantify potential financial impact of incidents to justify preventive investment
Cost-of-breach models estimate the financial consequences of security incidents, enabling leaders to demonstrate that prevention investments are economically rational.
Question 3: A CSL leader must allocate a limited security budget across competing priorities. What framework best supports this decision?
- Risk-based prioritization aligning investments to highest-likelihood, highest-impact threats (Correct answer)
- Spending equally across all security domains
- Allocating budget based on team size
- Prioritizing the lowest-cost controls first
Correct answer: Risk-based prioritization aligning investments to highest-likelihood, highest-impact threats
Risk-based prioritization directs the most resources toward controls that address the most likely and impactful threats, maximizing security value from constrained budgets.
Question 4: Which budget category typically represents the largest proportion of cybersecurity spending?
- Personnel costs (salaries, benefits, and training for security staff) (Correct answer)
- Hardware purchases
- Travel and conference fees
- Office supplies
Correct answer: Personnel costs (salaries, benefits, and training for security staff)
Personnel costs consistently represent the largest share of cybersecurity budgets because skilled security professionals command high salaries and are difficult to retain.
Question 5: What is the purpose of a cybersecurity business case when requesting budget increases?
- Translate security needs into business risk and financial terms that executive decision-makers can evaluate (Correct answer)
- List all known security vulnerabilities to alarm the board
- Request identical budget to the previous year
- Describe technical security tool features in detail
Correct answer: Translate security needs into business risk and financial terms that executive decision-makers can evaluate
A security business case frames investment requests in terms of risk reduction, regulatory compliance, and financial impact rather than technical specifications that non-technical executives may not evaluate effectively.
Question 6: How does the concept of 'risk appetite' influence cybersecurity budget decisions?
- Organizations with lower risk appetite invest more in preventive controls to reduce exposure below their tolerance threshold (Correct answer)
- Risk appetite only affects marketing budgets
- Higher risk appetite always means higher security spending
- Risk appetite is set by IT staff, not leadership
Correct answer: Organizations with lower risk appetite invest more in preventive controls to reduce exposure below their tolerance threshold
Risk appetite defines how much residual risk leadership will accept; organizations with low risk tolerance must invest more in controls to reduce risk to acceptable levels.
Which financial metric helps a CSL leader justify cybersecurity investments to the board?