Strategic Planning Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Strategic Planning flashcards as text
A CISO is preparing a 5-year security strategy immediately following a major data breach. Which element should receive HIGHEST priority in the early phases?
Answer: Immediate capability gaps in detection and response exposed by the breach
Post-breach strategic planning must first address the specific capability failures exposed by the incident before focusing on longer-term transformation.
Which planning technique helps a CISO identify which security initiatives are time-sensitive versus those that can be sequenced later?
Answer: Critical path method (CPM)
Critical path method identifies the sequence of dependent tasks that determine the minimum time to complete a strategic initiative.
In strategic planning, which output BEST communicates the security program's current status and forward trajectory to board-level stakeholders?
Answer: An executive security dashboard with KPIs, KRIs, and roadmap milestones
Executive dashboards summarize program health through key performance and risk indicators at a level appropriate for board-level decision-making.
When a CISO develops security strategy for an organization operating in a heavily regulated industry, regulatory compliance requirements should be treated as:
Answer: A baseline constraint, with risk-driven priorities built above that floor
Compliance sets a minimum required baseline; effective security strategy layers risk-driven controls above that floor to address actual threats.
A CISO incorporates lessons learned from peer organizations' breaches into the strategic plan. This practice is an example of:
Answer: Cyber threat intelligence integration into strategic planning
Using external breach intelligence to inform strategic decisions is a core application of cyber threat intelligence at the strategic planning level.
Which scenario BEST illustrates misalignment between security strategy and business strategy?
Answer: The security team blocks a merger due to undisclosed cyber risks
If security risks from a merger are not surfaced until they cause a blockage, the security program is reactive rather than integrated with business strategy.
A CISO wants to quantify the financial return of security controls to justify budget increases. The MOST appropriate method is:
Answer: Return on Security Investment (ROSI) analysis using risk reduction and loss expectancy
ROSI calculates expected loss reduction against control cost, providing a financial justification framework for security investment decisions.