CCISO (712-50) Executive Decision Simulation
Executive Briefing
You have recently been appointed as the first Chief Information Security Officer (CISO) of a rapidly expanding SaaS provider preparing for an IPO. The executive board is overwhelmed by disjointed reports of vulnerabilities, compliance gaps, and third-party threats coming from IT, Legal, and HR.
Business Context
- Business Objective: Achieve a unified, mature Enterprise Risk Management (ERM) posture to satisfy institutional investors.
- Current State: Risks are managed ad-hoc in spreadsheets siloed by department. There is no single source of truth for the board to review organizational risk exposure.
- Governance Mandate: You must establish a formal risk management lifecycle, starting with the implementation of a centralized Risk Register.
Decision Scenario
During the inaugural ERM committee meeting, department heads express confusion about the new governance requirements. The Director of IT believes the Risk Register is a project plan for patching servers, while the Legal Counsel thinks it’s an audit schedule. You need to clearly define the fundamental purpose of a Risk Register to align the executive team on its role in corporate governance.
Question
The primary purpose of a risk register is to:
Strategic Analysis
1. What is the real problem
The organization lacks executive visibility into its threat landscape. Without a centralized ledger, leadership cannot prioritize investments, assign accountability, or make informed decisions regarding risk acceptance, transfer, or mitigation.
2. Business vs security perspective
Technologists often confuse the act of documenting a risk with the act of fixing a risk. A CISO must separate the two: you cannot effectively develop mitigation strategies across an enterprise until you have an exhaustive, agreed-upon log of what those risks actually are.
3. Risk and impact analysis
If the Risk Register is treated as a mitigation plan (a "to-do list"), risks that the business chooses to accept or transfer will be left off the document, resulting in dangerous blind spots for the board.
4. Why correct answer is BEST
A. Maintain a log of discovered risks is the correct answer. A risk register is fundamentally a centralized repository. It acts as the master ledger documenting every identified risk, its owner, its current probability/impact score, and its treatment status. It provides the single pane of glass required for executive oversight.
5. Why other options are weaker
B & D. Tracking and coordinating risk assessments describes the operational schedule of risk management, not the purpose of the register itself.
C. Developing mitigation plans is the purpose of a Risk Treatment Plan (or Plan of Action and Milestones - POAM). The register logs the risk; the treatment plan defines the response.
MINI LESSON: The Risk Management Lifecycle
- Risk Assessment: The process of identifying and evaluating threats (The Input).
- Risk Register: The centralized log of all assessed risks and their current status (The Ledger).
- Risk Treatment: The executive decision to mitigate, transfer, accept, or avoid the logged risk (The Action).