โ† All CCISO Flashcard Decks

Financial Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Financial Management flashcards as text
  1. A CISO needs to justify a $500,000 security investment to the board. Which financial metric best demonstrates the investment's value by comparing potential loss reduction to cost?

    Answer: Return on Security Investment (ROSI)

    ROSI specifically quantifies security investment value by calculating how much risk (potential loss) is reduced relative to the cost of the control.

  2. During budget planning, a CISO discovers that the organization's cyber insurance premium is increasing 40% due to poor security posture. How should this be classified in the security budget?

    Answer: Operational expenditure (OpEx)

    Insurance premiums are recurring operational costs classified as OpEx, not one-time capital investments.

  3. A CISO is building a Total Cost of Ownership (TCO) model for a new SIEM platform. Which component is most commonly underestimated in TCO calculations?

    Answer: Integration, training, and ongoing maintenance costs

    TCO models often underestimate indirect costs like staff training, system integration labor, and ongoing maintenance, which frequently exceed initial procurement costs.

  4. A company allocates its security budget using a percentage of IT budget model. What is the primary weakness of this approach compared to risk-based budgeting?

    Answer: It fails to account for the organization's specific threat landscape and risk profile

    Percentage-of-IT budgeting is a benchmarking shortcut that ignores the organization's unique risks, industry threats, and regulatory requirements.

  5. When presenting a security budget variance to the CFO, the CISO notes spending exceeded the incident response line item by 200% due to a ransomware event. How should this be categorized?

    Answer: Unfavorable variance requiring reforecast

    Unplanned cost overruns driven by security incidents represent unfavorable variances that require budget reforecast and updated financial planning.

  6. A CISO is evaluating whether to build an internal SOC or outsource to an MSSP. Which financial analysis technique is most appropriate for comparing these two multi-year options?

    Answer: Net Present Value (NPV) analysis

    NPV analysis accounts for the time value of money across multi-year cost streams, making it ideal for comparing build-vs-buy decisions with different upfront and recurring costs.

  7. Under a zero-based budgeting (ZBB) model, what must a CISO do differently compared to incremental budgeting?

    Answer: Justify every security expenditure from scratch each budget cycle

    Zero-based budgeting requires justifying all spending from a zero baseline each cycle, rather than simply adjusting the prior year's approved budget.