Strategic Planning Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Strategic Planning flashcards as text
A CISO uses Porter's Five Forces model during strategic planning. Which force directly relates to the risk posed by disruptive technology replacing existing security solutions?
Answer: Threat of substitute products
The threat of substitutes captures the risk that alternative technologies or approaches could render current security tools obsolete.
In strategic planning, 'capability maturity' assessments help a CISO to:
Answer: Benchmark current security practices against a defined scale to prioritize improvements
Capability maturity models (e.g., CMM, C2M2) measure process maturity on a defined scale and guide investment in areas needing improvement.
Which document typically serves as the top-level policy artifact that gives the CISO authority to enforce the security strategy?
Answer: Information security charter
An information security charter (or policy) establishes executive-level mandate for security governance and the CISO's authority.
When prioritizing strategic security initiatives, a CISO should PRIMARILY consider:
Answer: Risk reduction value relative to business impact and available resources
Initiative prioritization must weigh risk reduction potential against business impact and resource constraints for maximum strategic value.
A gap analysis in security strategic planning compares which two states?
Answer: Current security posture vs. desired future-state security posture
A gap analysis identifies the delta between where the organization is today and where it needs to be to meet strategic security objectives.
Which of the following BEST describes a security strategy's 'strategic objective'?
Answer: A broad, measurable outcome the security program aims to achieve over the planning period
Strategic objectives are high-level, measurable outcomes (e.g., 'achieve ISO 27001 certification within 2 years') that guide program direction.
A CISO presents a security strategy to the board but receives pushback that it conflicts with a planned acquisition. This scenario highlights the importance of:
Answer: Integrating security strategy into enterprise strategic planning cycles
Security strategy must be synchronized with enterprise planning cycles so that major business events like acquisitions are considered from the outset.