Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: The chief information security officer (CISO) of…

You are the chief information security officer (CISO) of a large healthcare organization that handles protected health information (PHI). The organization has recently been acquired by a larger conglomerate, and the new parent company mandates that all subsidiaries adopt a single, unified risk management framework based on NIST SP 800-39. Your current framework is ISO 27005-based and has been effective for years. During the transition, you discover that the parent company's framework requires quantitative risk analysis for all critical assets, while your team has been primarily using qualitative analysis due to lack of accurate financial data. Moreover, the parent company expects all risk assessments to be completed within 30 days, a timeframe your team considers unrealistic given the number of assets. Several key stakeholders are concerned about the additional resource burden and potential disruption to operations. You need to propose a course of action that balances compliance with the parent company's mandate while maintaining operational effectiveness and minimizing risk to patient data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a gap analysis between ISO 27005 and NIST SP 800-39, then develop a phased transition plan with a longer timeline, presenting it to the parent company's board for approval.

The best course of action because it respects both the parent company's mandate and the organization's operational reality. A gap analysis between ISO 27005 and NIST SP 800-39 identifies specific differences and allows a phased transition plan with a longer timeline, which can be presented to the parent company for approval. This approach balances compliance with operational effectiveness, addresses stakeholder concerns about resource burden and disruption, and minimizes risk to patient data. Option B is non-compliant and may lead to conflict with the parent company. Option C provides a short-term fix but does not address the long-term requirement to adopt the unified framework. Option D is too aggressive and unrealistic, risking operational disruption and potential compromise of patient data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a gap analysis between ISO 27005 and NIST SP 800-39, then develop a phased transition plan with a longer timeline, presenting it to the parent company's board for approval.

    Why this is correct

    A gap analysis between ISO 27005 and NIST SP 800-39 is a critical first step to identify specific differences in risk management methodologies, control sets, and reporting requirements. Developing a phased transition plan allows for systematic integration, training, and resource allocation, minimizing operational disruption while ensuring thorough adoption. Presenting this strategic roadmap to the parent company's board secures essential executive buy-in, funding, and alignment with overall corporate governance and risk appetite.

  • Continue using ISO 27005 and argue that it is equally valid, citing the principle of risk management flexibility and the disruption that a transition would cause.

    Why it's wrong here

    Refusing to adopt the mandated NIST framework directly contradicts the parent company's directive, undermining the CISO's role in upholding corporate governance and compliance. While ISO 27005 is a valid and recognized framework, ignoring a clear organizational mandate for 'flexibility' demonstrates a lack of strategic alignment and could severely damage the CISO's credibility and the security program's standing within the enterprise.

  • Hire external consultants to perform the quantitative assessments, allowing the internal team to focus on existing operations, and accept the cost as a business necessity.

    Why it's wrong here

    Hiring external consultants solely to perform quantitative assessments is a superficial solution that fails to build internal capability or integrate the NIST framework into the organization's long-term risk management processes. This approach creates an unsustainable dependency on external parties, prevents the internal team from developing crucial expertise in the new methodology, and does not address the systemic change required for a successful, enduring framework transition.

  • Immediately adopt the NIST framework and begin quantitative assessments, using industry-standard cost estimates to expedite the process within 30 days.

    Why it's wrong here

    Attempting to immediately adopt a complex framework like NIST SP 800-39 and conduct comprehensive quantitative assessments within an unrealistic 30-day timeframe is technically infeasible and highly irresponsible. Such an expedited process would inevitably lead to superficial analysis, inaccurate risk assessments, significant operational disruption, and severe team burnout, compromising the integrity and effectiveness of the entire security program.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.