Enhance your strategic thinking. This simulation trains you to evaluate business impact, understand governance decisions, and select the best executive path.
You are the Chief Information Security Officer (CISO) for a mid-sized financial services firm. A peer executive, the VP of Sales, approaches you informally to request immediate access to the email account of one of their direct reports. They cite an urgent internal matter but wish to handle it "quietly and quickly."
The organization operates in a highly regulated environment. To protect the firm's assets, there is a prominent "no right to privacy" notice on all corporate logon screens, and all employees have signed an Acceptable Use Policy (AUP) acknowledging this condition. While the company legally retains the right to monitor communications, the Board of Directors expects all internal investigations to strictly adhere to the established risk management and compliance frameworks to prevent legal liabilities and HR disputes.
Your relationship with the VP of Sales is excellent, and you want to be a business enabler. Technically, your team can grant access in less than a minute. However, granting access purely on informal verbal authorization—even with an AUP in place—bypasses standard governance controls. You must balance supporting a peer executive's urgent request with enforcing the enterprise control framework to protect the organization from undocumented risks.
1. What is the real problem?
Informal requests bypass governance controls. Even if an action is legally permissible under company policy, executing it without a formal, documented paper trail creates unmanaged HR and legal liabilities.
2. Business vs. Security Perspective
The business unit (VP of Sales) wants speed, agility, and discretion to manage their team. Security and Governance require auditability, proper authorization, and process adherence to protect the enterprise from internal disputes or external litigation.
3. Risk and Impact Analysis
Undocumented access can invalidate findings in an internal investigation. If the employee is terminated based on this access and sues, the lack of a formal authorization process demonstrates a breakdown of internal controls, exposing the company to significant financial and reputational damage.
4. Why the correct answer (D) is BEST
Option D strictly adheres to the governance framework while still supporting the business. It enforces the separation of duties and ensures non-repudiation. By requiring the appropriate level of management/HR sign-off, you create an audit trail and appropriately shift the risk acceptance from the IT/Security department to the authorized business leader.
5. Why other options are weaker:
6. Mini Lesson: Governance & Alignment
Governance is not merely about writing policies; it is about enforcing the processes that execute those policies safely. An Acceptable Use Policy grants the organization the right to monitor, but robust internal controls dictate exactly who can authorize that monitoring. This ensures actions are legally defensible and aligned with risk tolerance.
Explore more CCISO simulations to sharpen your executive decision-making.
Visit Practice Tests →