ExamRange
Home ExamRange Practice Tests

CCISO (712-50) Executive Decision Simulation

This simulation tests your strategic understanding of organizational structure and conflict of interest mitigation. You will act as the CISO defining fundamental governance boundaries to external auditors and the board.

Executive Briefing

You are the CISO of GlobalTech Enterprise. The organization recently underwent a major merger. To streamline operations and cut costs, the Chief Information Officer (CIO) has proposed merging the Network Engineering team and the Information Security team into a single "Unified TechOps" department. The Board of Directors and external SOX auditors are reviewing this proposal for approval.

Business Context

Decision Scenario

As the CISO, you must formally advise the Board on the CIO's proposal. You must defend the organizational structure by highlighting which operational functions cannot be legally or ethically combined without creating massive risk to the enterprise's integrity and compliance standing.

Question

Which represents PROPER separation of duties in the corporate environment?
Hint: Think about oversight and implementation. Can the people responsible for building and maintaining the infrastructure also be the ones who audit it for security vulnerabilities?

Strategic Analysis

1. What is the real problem

The business is attempting to prioritize speed and cost over fundamental governance. Merging the implementers (Network) with the auditors (Security) creates a severe conflict of interest, negating the ability to perform objective risk assessments and fraud prevention.

2. Business vs Security Perspective

From a business perspective, merging teams looks like a straightforward path to reducing headcount and streamlining workflows. From a security perspective, removing the "check and balance" between operations and security invalidates the entire governance model, making external audits impossible to pass.

3. Risk and Impact Analysis

If the Network team is also the Information Security team, they could configure an insecure firewall rule to make their own job easier, and then sign off on the security of that rule themselves. This destroys accountability, violates SOX and ISO frameworks, and introduces catastrophic insider threat vectors.

4. Why the Correct Answer is BEST (A)

Separation of Duties (SoD) mandates that critical functions must be divided among different people/teams to prevent error or fraud. Information Security and Network operations are distinct functions. The Network team focuses on availability and connectivity (building the infrastructure). The Information Security team focuses on confidentiality and integrity (auditing and securing the infrastructure). You cannot objectively audit your own work.

5. Why Other Options are Weaker

B. InfoSec and IAM perform distinct functions: While often separate, Identity and Access Management (IAM) is actually frequently nested *under* Information Security as an operational security function. It does not represent the critical, fundamental boundary required by SoD like separating Network and Security does.

C. Finance access to HR data: Giving Finance broad access to HR data violates both SoD and the Principle of Least Privilege. They should only have access to specific payroll inputs, not complete HR records.

D. Developers and Network having admin rights: This is a catastrophic violation of SoD. Developers should not have administrative access to production servers (Network/Ops domain); they should only have access to development environments.

MINI LESSON: Separation of Duties (SoD)

SoD is a foundational control in Risk Management designed to ensure no single individual or team has total control over a transaction or process. To achieve SoD, divide processes into four phases: Authorization, Execution, Custody, and Auditing. No one team should own more than one phase. Network executes; Security audits.

EXECUTIVE TAKEAWAY: Those who build and operate the infrastructure cannot be the same people who audit and secure it.

Refine Your Executive Intuition

Master the CCISO 712-50 domains by bridging the gap between technical security and business leadership.

Explore more CCISO simulations