CSL Strategic Planning & Leadership in Cybersecurity 3 — Questions and Answers
Question 1: A CISO is presenting a security investment proposal to the CFO. Which approach BEST demonstrates the financial justification for a new security control?
- Show the number of threats blocked last year
- Calculate the Return on Security Investment (ROSI) using risk reduction (Correct answer)
- Reference peer organization spending benchmarks
- List all compliance requirements addressed
Correct answer: Calculate the Return on Security Investment (ROSI) using risk reduction
ROSI quantifies risk reduction in financial terms, allowing security investments to be evaluated using the same criteria as other business investments.
Question 2: Which of the following BEST describes the concept of 'security by design' in strategic planning?
- Adding security controls after systems are deployed
- Integrating security requirements into projects from inception (Correct answer)
- Purchasing security tools from a single vendor
- Encrypting all data at rest
Correct answer: Integrating security requirements into projects from inception
Security by design means embedding security considerations into the planning and development phases of any initiative rather than retrofitting them later.
Question 3: A cybersecurity leader must manage competing priorities between security hardening and business agility. What strategic approach BEST resolves this tension?
- Always prioritize security over business speed
- Adopt a risk-based approach with agreed risk appetite thresholds (Correct answer)
- Delegate all decisions to the business units
- Implement all controls simultaneously to minimize delay
Correct answer: Adopt a risk-based approach with agreed risk appetite thresholds
A risk-based approach with defined risk appetite thresholds allows informed trade-offs between security rigor and operational velocity.
Question 4: Which document formally defines the boundaries of authority and accountability for the CISO within an organization?
- Information Security Policy
- CISO Charter (Correct answer)
- Business Continuity Plan
- Risk Register
Correct answer: CISO Charter
A CISO Charter formally establishes the role's mandate, reporting lines, authority, and accountability within the organization.
Question 5: An organization's threat landscape has significantly evolved. What is the FIRST step a cybersecurity leader should take to update the security strategy?
- Deploy additional security tools immediately
- Conduct a revised threat and risk assessment (Correct answer)
- Issue a new acceptable use policy
- Increase the security operations budget
Correct answer: Conduct a revised threat and risk assessment
Updating the threat and risk assessment ensures that strategy changes are grounded in an accurate current understanding of threats and vulnerabilities.
Question 6: Which of the following is an example of a LEADING indicator of cybersecurity program effectiveness?
- Number of data breaches in the past year
- Percentage of staff who completed phishing simulation training (Correct answer)
- Cost of incident response in Q3
- Number of regulatory fines received
Correct answer: Percentage of staff who completed phishing simulation training
Leading indicators like training completion rates predict future security posture, whereas lagging indicators like breaches measure past failures.
Question 7: A merger brings a second organization into the enterprise. What is the HIGHEST priority cybersecurity action during the integration planning phase?
- Deploying uniform endpoint protection across both organizations
- Conducting a security due diligence assessment of the acquired entity (Correct answer)
- Migrating all systems to the parent company's network
- Updating the acceptable use policy to cover new employees
Correct answer: Conducting a security due diligence assessment of the acquired entity
Security due diligence identifies inherited risks, vulnerabilities, and compliance gaps before integration can be safely planned.
A CISO is presenting a security investment proposal to the CFO.
Which approach BEST demonstrates the financial justification for a new security control?