Financial Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Financial Management flashcards as text
A CISO discovers that shadow IT spending on unsanctioned SaaS tools totals $1.2M annually. What is the primary financial governance risk this presents?
Answer: Unmanaged vendor risk, data exposure, and lack of budgetary control outside procurement oversight
Shadow IT creates financial governance failures including uncontrolled vendor risk, data security exposure, and spending that bypasses procurement controls and budget accountability.
When calculating the cost of a data breach for financial planning purposes, which category of cost is most frequently omitted in initial estimates?
Answer: Reputational damage and customer churn
Long-term reputational damage leading to customer attrition is the most frequently underestimated breach cost category because it manifests over months to years after the incident.
A CISO is asked to develop a security metrics dashboard for the CFO. Which metric most directly links security investment to financial performance?
Answer: Cost per security incident and reduction in ALE over time
Cost per incident and ALE reduction directly connect security program performance to financial outcomes, making them most relevant to CFO-level reporting.
A CISO must defend the security budget against cuts by showing how the program reduces financial risk. Which approach is most persuasive to a risk-aware board?
Answer: Present quantified risk reduction using threat modeling and expected loss calculations
Quantified risk reduction using financial modeling (ALE, ROSI) directly addresses board-level concern about financial exposure and is more persuasive than benchmarks or activity metrics.
An organization is considering self-insuring against cyber risk instead of purchasing cyber insurance. What is the key financial requirement for self-insurance to be viable?
Answer: The organization must maintain sufficient financial reserves to absorb maximum probable loss
Self-insurance requires adequate financial reserves to cover potential losses; without sufficient capital reserves, a major incident could be catastrophic to the organization's financial health.
A CISO is preparing a five-year security roadmap with associated budget projections. Which financial planning technique accounts for the decreasing value of future spending in today's dollars?
Answer: Discounted cash flow (DCF) analysis
Discounted cash flow analysis applies discount rates to future cash outflows to express them in present value terms, enabling accurate multi-year financial comparison.
A CISO negotiates a multi-year enterprise license agreement (ELA) for a security platform. What financial advantage does an ELA typically provide over annual licensing?
Answer: Provides price certainty and typically lower per-unit cost over the contract term
ELAs lock in pricing for the contract term, protecting against year-over-year price increases and typically offering volume discounts that reduce total cost compared to annual renewals.