โ† All CCISO Flashcard Decks

Financial Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Financial Management flashcards as text
  1. A CISO discovers that shadow IT spending on unsanctioned SaaS tools totals $1.2M annually. What is the primary financial governance risk this presents?

    Answer: Unmanaged vendor risk, data exposure, and lack of budgetary control outside procurement oversight

    Shadow IT creates financial governance failures including uncontrolled vendor risk, data security exposure, and spending that bypasses procurement controls and budget accountability.

  2. When calculating the cost of a data breach for financial planning purposes, which category of cost is most frequently omitted in initial estimates?

    Answer: Reputational damage and customer churn

    Long-term reputational damage leading to customer attrition is the most frequently underestimated breach cost category because it manifests over months to years after the incident.

  3. A CISO is asked to develop a security metrics dashboard for the CFO. Which metric most directly links security investment to financial performance?

    Answer: Cost per security incident and reduction in ALE over time

    Cost per incident and ALE reduction directly connect security program performance to financial outcomes, making them most relevant to CFO-level reporting.

  4. A CISO must defend the security budget against cuts by showing how the program reduces financial risk. Which approach is most persuasive to a risk-aware board?

    Answer: Present quantified risk reduction using threat modeling and expected loss calculations

    Quantified risk reduction using financial modeling (ALE, ROSI) directly addresses board-level concern about financial exposure and is more persuasive than benchmarks or activity metrics.

  5. An organization is considering self-insuring against cyber risk instead of purchasing cyber insurance. What is the key financial requirement for self-insurance to be viable?

    Answer: The organization must maintain sufficient financial reserves to absorb maximum probable loss

    Self-insurance requires adequate financial reserves to cover potential losses; without sufficient capital reserves, a major incident could be catastrophic to the organization's financial health.

  6. A CISO is preparing a five-year security roadmap with associated budget projections. Which financial planning technique accounts for the decreasing value of future spending in today's dollars?

    Answer: Discounted cash flow (DCF) analysis

    Discounted cash flow analysis applies discount rates to future cash outflows to express them in present value terms, enabling accurate multi-year financial comparison.

  7. A CISO negotiates a multi-year enterprise license agreement (ELA) for a security platform. What financial advantage does an ELA typically provide over annual licensing?

    Answer: Provides price certainty and typically lower per-unit cost over the contract term

    ELAs lock in pricing for the contract term, protecting against year-over-year price increases and typically offering volume discounts that reduce total cost compared to annual renewals.