A newly appointed CISO at a mid-sized manufacturing firm finds that the information security programme has historically been driven entirely by the IT department, with controls selected by engineers based on technical merit. The board has asked the CISO to demonstrate that security investment is aligned with the business. Which action should the CISO take FIRST to establish governance alignment?
- AEngage with executive leadership to identify business objectives, risk appetite, and critical assets before defining a security strategy. Correct
- BAdopt the NIST Cybersecurity Framework and map all existing technical controls to its categories to show coverage.
- CCommission an external penetration test to baseline the current technical posture and report findings to the board.
- DRestructure the security team to report directly to the CEO and publish an updated information security policy.
Why A is correct: Governance alignment begins by understanding mission, objectives, and risk appetite from senior leadership; only then can the security strategy be shaped to support, rather than constrain, the business.
Why B is wrong: Mapping controls to a framework is useful but it documents what already exists rather than confirming the programme supports the business mission, so it answers the wrong question first.
Why C is wrong: A penetration test produces a technical snapshot but does not address the governance gap the board raised; tactical findings without strategic context perpetuate the IT-led problem.
Why D is wrong: Reporting line changes and a fresh policy are reasonable later actions, but they will lack credibility until the CISO can show the strategy reflects what leadership actually values.