CCISO (712-50) Executive Decision Simulation
Executive Briefing
You are the CISO of a regional bank currently undergoing a major digital transformation. Your security architecture team has identified several aging perimeter firewalls that are currently functioning normally but are projected to fail under the increased load expected in the next quarter.
You need to mandate a strategic upgrade. However, the bank has a rigid IT Service Management (ITSM) framework overseen by the Change Advisory Board (CAB) to ensure absolute stability of financial transactions.
Business Context
Risk Appetite: Near-zero tolerance for unplanned downtime or security breaches. All modifications to the production environment must be meticulously documented and approved.
Current State: Moving from a reactive "break-fix" IT culture to a proactive security governance model.
Decision Scenario
To avoid a critical failure during peak operations next quarter, your team must alter the production environment now. You must align this proactive security upgrade with the enterprise's strict governance framework to ensure it receives funding and CAB approval without causing an unplanned outage.
Question
Which of the following activities results in change requests?
Strategic Analysis
1. What is the Real Problem?
The core issue is transitioning from a reactive security posture to a proactive one within a highly regulated environment. Unplanned changes—even well-intentioned ones meant to secure the environment—can cause catastrophic business disruption.
2. Business vs Security Perspective
Security sees an aging firewall as a risk that needs immediate mitigation. The business sees any modification to the production environment as a risk to revenue generation. IT Governance (like ITIL) bridges this gap through formal Change Management processes.
3. Risk and Impact Analysis
If you wait for the firewalls to fail (requiring Corrective Action), you suffer an outage, financial loss, and regulatory fines. If you proactively upgrade them (Preventive Action) without a Change Request, you risk causing the exact outage you were trying to prevent due to a lack of testing and coordination.
4. Why the Correct Answer is BEST
C. Preventive actions: Preventive actions are intentional, proactive measures taken to reduce the probability of negative consequences associated with project risks. Because they involve modifying the current baseline (systems, processes, or configurations) to avert a future problem, they inherently trigger the formal Change Request process to ensure the mitigation doesn't introduce new, unmanaged risks.
5. Why Other Options are Weaker
A & B (Corrective actions / Defect repair): While these *can* result in change requests, they are reactive measures responding to an incident or flaw that has already materialized. In executive governance, the strategic priority is shifting toward *preventive* measures to avoid the need for corrective actions entirely.
D (Inspection): Inspection is an audit or review process. It identifies risks or compliance gaps but does not, by itself, alter the environment. An inspection may *lead* to a preventive action, which then requires the change request.
MINI LESSON: Security & IT Service Management (ITSM)
- Proactive Governance: Mature security programs focus heavily on Preventive Actions to minimize business disruption and incident response costs.
- The Role of the CAB: The Change Advisory Board exists not to block security initiatives, but to evaluate the business impact of proposed preventive changes.
- Change Requests as Enablers: A formal Change Request is the vehicle a CISO uses to safely inject preventive security measures into the business's operational flow.
Elevate your Executive Leadership Skills
Prepare for the CCISO exam with scenarios designed for future CISOs.
Explore more CCISO simulations