ExamRange
Home ExamRange Practice Tests

In this simulation, you will learn how to align major capital expenditures (CapEx) with business risk requirements. Understanding which governance document drives technical budgeting is crucial for an executive security leader.

CCISO (712-50) Executive Decision Simulation

Executive Briefing

You are the CISO of a major cloud-hosted CRM platform. Following a severe regional weather event that nearly took your primary data center offline, the Board of Directors has mandated the construction of a secondary data center. You are sitting in a capital planning meeting with the CFO and the CIO. The CIO is requesting $15 million to build an identical, "Active-Active" mirrored facility. The CFO is pushing back, wanting to spend only $2 million on a bare-bones "Cold Site."

Business Context

Business Objectives: Maintain SLA commitments for enterprise clients while aggressively managing the company's operating margins.

Risk Appetite: The business cannot tolerate more than 4 hours of downtime for core database services, but can tolerate up to 48 hours for reporting and analytics modules.

Constraints: Capital expenditure (CapEx) is heavily scrutinized this quarter. Every dollar spent on IT infrastructure must be explicitly justified by pre-approved corporate governance documentation.

Decision Scenario

The CFO turns to you and asks: "We shouldn't be guessing at these budget numbers based on what IT *wants*, nor should we be arbitrarily cutting costs and risking the business. What official governance document gives us the exact requirements we need to build this budget accurately?"

Question

While designing a secondary data center for your company what document needs to be analyzed to determine to how much should be spent on building the data center?