Strategic Planning Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Strategic Planning flashcards as text
Which governance structure BEST ensures security strategic decisions receive appropriate executive-level oversight?
Answer: A security steering committee with C-suite and board representation
A security steering committee with executive and board members ensures strategic security decisions are vetted at the appropriate level of authority.
In the context of CCISO strategic planning, 'strategic risk' is BEST defined as:
Answer: Risks that could prevent the organization from achieving its long-term business objectives
Strategic risk refers to high-level uncertainties that threaten the organization's ability to execute its long-term strategy.
A CISO adopts an 'assume breach' philosophy in strategic planning. This approach PRIMARILY affects which planning element?
Answer: Detection, response, and recovery capability investments
Assume breach shifts strategic focus from prevention-only to robust detection, response, and recovery, accepting that perimeter breaches will occur.
When integrating cybersecurity into enterprise risk management (ERM), the CISO's role is to:
Answer: Translate cyber risks into business-impact terms understood by risk and finance executives
The CISO bridges the gap between technical cyber risk and business risk language so that cyber risks are properly reflected in the ERM framework.
Which approach ensures that security strategic planning remains relevant as the threat landscape evolves?
Answer: Embedding continuous threat intelligence review cycles into strategic planning
Incorporating ongoing threat intelligence into planning cycles ensures the strategy adapts to emerging risks without waiting for a full planning refresh.
A CISO's strategic plan includes a zero-trust network architecture initiative. Which business driver MOST likely justified this investment?
Answer: Increasing remote work and cloud adoption that eroded traditional perimeter controls
Zero-trust architectures are primarily driven by the dissolution of network perimeters due to remote work, cloud services, and mobile devices.
What is the primary purpose of a security program charter in strategic planning?
Answer: To formally establish scope, authority, accountability, and objectives of the security program
A security program charter defines mandate, scope, roles, authorities, and goals, providing the foundational governance document for the program.