CSL CSL Security Budgeting & Program Management 1 — Questions and Answers
Question 1: Which method is most effective for justifying cybersecurity budget increases to a CFO or board?
- Listing technical threats and CVE counts
- Quantifying risk in financial terms using frameworks like FAIR (Correct answer)
- Citing industry benchmark spending percentages only
- Presenting the number of security incidents blocked
Correct answer: Quantifying risk in financial terms using frameworks like FAIR
The FAIR (Factor Analysis of Information Risk) framework translates cyber risks into quantified financial loss exposure, which directly supports financial decision-making.
Question 2: A CISO is building the annual security budget. Which category typically represents the largest portion of a mature security program's budget?
- Security awareness training
- Technology and tooling (Correct answer)
- Security certifications for staff
- Penetration testing
Correct answer: Technology and tooling
Technology and tooling (SIEM, EDR, IAM, firewalls, etc.) typically constitute the largest proportion of enterprise cybersecurity budgets.
Question 3: What is a key benefit of using a security maturity model when presenting the security program to the board?
- It eliminates the need for annual security audits
- It provides a structured roadmap showing current state, target state, and progress (Correct answer)
- It replaces the need for penetration testing
- It automatically allocates budget across security domains
Correct answer: It provides a structured roadmap showing current state, target state, and progress
Maturity models like CMMI or NIST CSF tiers give boards a clear, structured picture of where the security program stands and what investment is needed to advance.
Question 4: Which approach best helps a CISO prioritize security investments when budget is constrained?
- Invest equally across all security domains
- Align spending to the highest-probability, highest-impact risks identified in the risk register (Correct answer)
- Follow peer organization benchmarks regardless of your specific risk profile
- Purchase the newest available security technologies
Correct answer: Align spending to the highest-probability, highest-impact risks identified in the risk register
Risk-based prioritization ensures that limited budget is concentrated on the threats most likely to materially harm the organization.
Question 5: What does a cybersecurity program charter formally establish?
- A list of approved security vendors
- The authority, scope, objectives, and governance structure of the security program (Correct answer)
- The technical architecture of security tools
- Employee security training requirements
Correct answer: The authority, scope, objectives, and governance structure of the security program
A program charter grants formal authority to the security program, defines its scope, and establishes governance mechanisms — essential for enterprise-wide security enforcement.
Question 6: How should a CISO handle a situation where the security budget is cut significantly mid-year?
- Continue all programs and absorb costs through deficit spending
- Re-prioritize based on risk, document trade-offs, and present accepted risk to leadership (Correct answer)
- Immediately outsource all security functions to reduce costs
- Eliminate security awareness training first as lowest-impact
Correct answer: Re-prioritize based on risk, document trade-offs, and present accepted risk to leadership
Re-prioritizing based on risk, documenting trade-offs, and formally presenting accepted risk to leadership ensures accountability and informed decision-making under budget constraints.
Which method is most effective for justifying cybersecurity budget increases to a CFO or board?