CSL Strategic Planning & Leadership in Cybersecurity 2 — Questions and Answers
Question 1: A CISO needs to align the cybersecurity strategy with business objectives. Which framework is MOST appropriate for mapping security controls to business value?
- NIST Cybersecurity Framework
- COBIT 2019
- ISO 27001
- SABSA (Correct answer)
Correct answer: SABSA
SABSA (Sherwood Applied Business Security Architecture) is specifically designed to derive security architecture directly from business requirements and objectives.
Question 2: When developing a multi-year cybersecurity roadmap, what should be the PRIMARY driver for prioritizing initiatives?
- Compliance deadlines
- Risk-adjusted business impact (Correct answer)
- Vendor recommendations
- Industry benchmarking data
Correct answer: Risk-adjusted business impact
Prioritizing by risk-adjusted business impact ensures that security investments address the most significant threats to organizational value.
Question 3: An organization's board requests a cybersecurity strategy presentation. Which metric is MOST effective for demonstrating program maturity to non-technical executives?
- Number of vulnerabilities patched per quarter
- Mean time to detect and respond to incidents (Correct answer)
- Percentage of endpoints with EDR deployed
- Total number of security policies in place
Correct answer: Mean time to detect and respond to incidents
MTTD and MTTR metrics directly reflect operational resilience and are meaningful to executives because they represent real business risk reduction.
Question 4: Which leadership style is MOST effective when a cybersecurity leader must drive rapid adoption of new security controls across resistant business units?
- Laissez-faire
- Transformational (Correct answer)
- Transactional
- Autocratic
Correct answer: Transformational
Transformational leadership inspires change through vision and motivation, making it most effective for driving cultural adoption of security practices.
Question 5: A company is expanding internationally. Which factor should the cybersecurity strategy address FIRST when entering a new jurisdiction?
- Firewall configuration standards
- Local data sovereignty and privacy laws (Correct answer)
- Employee security awareness training
- Endpoint management solutions
Correct answer: Local data sovereignty and privacy laws
Data sovereignty and local privacy laws (e.g., GDPR, PDPA) create legal obligations that must shape the security architecture before operations begin.
Question 6: What is the PRIMARY purpose of a cybersecurity governance committee at the executive level?
- To approve firewall rule changes
- To ensure security strategy aligns with risk appetite and business goals (Correct answer)
- To manage incident response during breaches
- To conduct vulnerability assessments
Correct answer: To ensure security strategy aligns with risk appetite and business goals
Executive governance committees exist to ensure that security strategy, investment, and risk tolerance are aligned with organizational objectives.
Question 7: When building a cybersecurity team, a leader is choosing between centralizing all security functions vs. embedding security in each business unit. What is the MAIN advantage of a federated model?
- Lower total cost of security operations
- Better alignment of security with each business unit's needs (Correct answer)
- Simplified compliance reporting
- Easier enforcement of uniform security policies
Correct answer: Better alignment of security with each business unit's needs
A federated model embeds security expertise within business units, enabling security decisions that are more contextually relevant to each unit's risk profile.
A CISO needs to align the cybersecurity strategy with business objectives.
Which framework is MOST appropriate for mapping security controls to business value?