Welcome to the CCISO Executive Decision Simulation. You will evaluate a strategic governance scenario, analyze business impact and risk, and make an executive-level leadership decision.
CCISO (712-50) Executive Decision Simulation
Executive Briefing
Current Stage: Enterprise Risk & Architecture Committee Meeting
Stakeholders: Chief Information Officer (CIO), Board of Directors, CISO (You)
FinServe Global has recently transitioned 60% of its workforce to a permanent remote model. Following a recent industry-wide spike in highly successful credential stuffing and phishing attacks, you (the CISO) propose mandating a secondary authentication process (MFA) for all external network access.
Business Context & Decision Scenario
The CIO strongly pushes back on your proposal. He argues that the IT support desk is already overwhelmed, and introducing a secondary authentication step will frustrate executives, disrupt sales workflows, and add significant administrative overhead. He states, "We already have complex password policies; adding another step is unnecessary busywork."
As the CISO, you must present this initiative not as an IT administrative burden, but as a fundamental architectural necessity to the Board of Directors. You need to frame the implementation in terms of recognized security governance principles.
Question
Creating a secondary authentication process for network access would be an example of?
Strategic Analysis
- What is the real problem: The business is prioritizing short-term operational convenience over long-term risk management. The CIO is viewing security controls as isolated administrative tasks rather than integrated enterprise risk controls.
- Business vs security perspective: The business often perceives additional authentication as "friction." Security governance recognizes that primary authentication (passwords) is inherently flawed and easily compromised. A secondary control is required to offset this residual risk.
- Risk and impact analysis: If remote access relies solely on passwords (a single layer), a single successful phishing email can result in a catastrophic data breach. Implementing a secondary process drastically reduces the likelihood of impact.
- Why correct answer is BEST (B): A secondary authentication process is the textbook definition of layered security (Defense in Depth). It introduces an independent control that must be bypassed if the primary control (password) fails, directly supporting resilient security architecture.
- Why other options are weaker:
A & D (Administrator time / Undue commitment): These options reflect a dangerous cultural mindset where security is viewed as an annoyance rather than a strategic business enabler. Governance requires balancing operational cost against enterprise risk.
C (Network segmentation): This is a completely different architectural concept used to isolate parts of a network to prevent lateral movement, not a mechanism for authenticating user identity.
A core principle of information security governance is the assumption that any single security control will eventually fail. "Defense in Depth" or "Layered Security" mitigates this reality by establishing multiple, overlapping, and independent defensive mechanisms. If an attacker bypasses the outer perimeter (e.g., stealing a password), a secondary inner layer (e.g., an MFA token, conditional access policy, or biometric prompt) halts their progression. This ensures there is no Single Point of Failure (SPOF) in the enterprise security posture.
Ready to refine your Executive Leadership skills further?
Enhance your CCISO preparation with more scenario-based strategic simulations.
Explore more CCISO simulations