Security Program Development & Management Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Program Development & Management flashcards as text
A CISO is tasked with establishing security metrics for the board. Which metric BEST demonstrates the business value of the security program?
Answer: Reduction in mean time to detect (MTTD) and respond (MTTR) to incidents
MTTD and MTTR directly tie security operational efficiency to business risk reduction, making them meaningful to board-level stakeholders.
When developing a security program charter, which element is MOST critical to include to ensure executive sponsorship?
Answer: Defined authority, scope, and accountability of the security function
A charter must define authority and scope so that executives understand and formally delegate responsibility to the CISO.
A security program is failing to align with business objectives. What is the FIRST step a CISO should take to remediate this?
Answer: Conduct a stakeholder analysis to understand business priorities
Understanding stakeholder priorities is the foundation for aligning security investments with the business objectives that matter most.
Which approach BEST describes integrating security into an organization's SDLC?
Answer: Embedding security requirements, reviews, and testing at every phase of development
A DevSecOps approach embeds security throughout all SDLC phases rather than treating it as a gate at the end.
A CISO must justify a security budget increase to the CFO. Which financial model is MOST effective?
Answer: Return on security investment (ROSI) tied to risk reduction
ROSI frames security spending in terms of quantified risk reduction, which is the language most compelling to financial executives.
What is the PRIMARY purpose of a security program roadmap?
Answer: To provide a prioritized, time-bound plan for maturing security capabilities
A roadmap gives leadership a clear view of where the program is headed, what capabilities will be built, and when.
Which governance structure BEST supports enterprise-wide security program accountability?
Answer: A security steering committee with cross-functional representation
A cross-functional steering committee ensures security decisions reflect business, legal, HR, and operational perspectives and shares accountability.