Financial Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Financial Management flashcards as text
A CISO needs to justify a $500,000 security investment to the board. Which financial metric best demonstrates the investment's value by comparing potential loss reduction to cost?
Answer: Return on Security Investment (ROSI)
ROSI specifically quantifies security investment value by calculating how much risk (potential loss) is reduced relative to the cost of the control.
During budget planning, a CISO discovers that the organization's cyber insurance premium is increasing 40% due to poor security posture. How should this be classified in the security budget?
Answer: Operational expenditure (OpEx)
Insurance premiums are recurring operational costs classified as OpEx, not one-time capital investments.
A CISO is building a Total Cost of Ownership (TCO) model for a new SIEM platform. Which component is most commonly underestimated in TCO calculations?
Answer: Integration, training, and ongoing maintenance costs
TCO models often underestimate indirect costs like staff training, system integration labor, and ongoing maintenance, which frequently exceed initial procurement costs.
A company allocates its security budget using a percentage of IT budget model. What is the primary weakness of this approach compared to risk-based budgeting?
Answer: It fails to account for the organization's specific threat landscape and risk profile
Percentage-of-IT budgeting is a benchmarking shortcut that ignores the organization's unique risks, industry threats, and regulatory requirements.
When presenting a security budget variance to the CFO, the CISO notes spending exceeded the incident response line item by 200% due to a ransomware event. How should this be categorized?
Answer: Unfavorable variance requiring reforecast
Unplanned cost overruns driven by security incidents represent unfavorable variances that require budget reforecast and updated financial planning.
A CISO is evaluating whether to build an internal SOC or outsource to an MSSP. Which financial analysis technique is most appropriate for comparing these two multi-year options?
Answer: Net Present Value (NPV) analysis
NPV analysis accounts for the time value of money across multi-year cost streams, making it ideal for comparing build-vs-buy decisions with different upfront and recurring costs.
Under a zero-based budgeting (ZBB) model, what must a CISO do differently compared to incremental budgeting?
Answer: Justify every security expenditure from scratch each budget cycle
Zero-based budgeting requires justifying all spending from a zero baseline each cycle, rather than simply adjusting the prior year's approved budget.