Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda. The CISO has been able to implement a number of technical controls and is able to influence the Information Technology teams but has not been able to influence the rest of the organization. From an organizational perspective, which of the following is the LIKELY reason for this? A. The CISO reports to the IT organization B. The CISO has not implemented a policy management framework C. The CISO does not report directly to the CEO of the organization D. The CISO has not implemented a security awareness program  Suggested Answer: A Community Answer: A This question is in 712-50 EC-Council Certified CISO (CCISO) Exam For getting EC-Council Certified CISO (CCISO) Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by EC-Council. Trademarks, certification & product names are used for reference only and belong to EC-Council. The website does not contain actual questions and answers from EC-Council's Certification Exam.
Please login or Register to submit your answer