ExamRange

CCISO (712-50) Executive Decision Simulation

Master strategic communication and budget justification. This simulation trains you to align security initiatives with executive priorities by correctly utilizing a formal business case.

Executive Briefing

You are the Chief Information Security Officer (CISO) for a rapidly expanding global manufacturing firm. The firm has recently acquired three smaller competitors, resulting in a highly fragmented and vulnerable Identity and Access Management (IAM) landscape.

You need to implement an enterprise-wide Zero Trust architecture to consolidate these identities. However, this is a multi-million dollar initiative requiring significant cross-departmental labor. The CFO and the Board of Directors are currently hesitant to approve the budget due to aggressive M&A capital constraints.

Business Context

  • Financial Constraints: The Board requires strict justification for all capital expenditures (CapEx) exceeding $500,000.
  • Risk Appetite: The business prioritizes operational uptime. A ransomware attack caused by poor access controls would be catastrophic to the newly integrated supply chains.
  • Executive Communication: The Board does not understand technical jargon (e.g., "Kerberos tickets" or "OAuth tokens"). They operate purely on financial metrics, risk exposure, and resource allocation.

Decision Scenario

Your Security Architecture team has presented a highly detailed 80-page technical design document outlining how the new Zero Trust system will defeat modern credential stuffing attacks and lateral movement.

You inform the team that the Board will not read a technical architecture document. Instead, you mandate the creation of a formal Business Case document to present at the next executive steering committee meeting.

To guide your team, you must clearly define the primary strategic purpose of bringing this specific document to the executive board.

Question

What are the primary reasons for the development of a business case for a security project?

A. To forecast usage and cost per software licensing
B. To understand the attack vectors and attack sources
C. To communicate risk and forecast resource needs
D. To estimate risk and negate liability to the company