@Aidah Nakyejwe Correct Answer: C. Present leadership a business case for the assessment budget Explanation (CISSP logic): This question flips the usual pattern on purpose. "Assess first" is the right instinct, but the scenario plants a constraint: leadership resists funding the analysis. Every security program rests on senior management support, and a CISO cannot execute an assessment leadership hasn't authorized or funded. When the blocker is management buy-in, obtaining that buy-in is Step 1. The business case translates security need into business language, which is the CISO's core job. Breakdown: A. The strong distractor, because it's our own mantra used against us. Assessment is the right destination, but conducting one over leadership's objection means running an unfunded, unsanctioned program. Authority precedes activity. B. Benchmarking against a framework proves conformity, not risk alignment. It's also the tempting shortcut for a resistant leadership team: "we match the framework" is compliance logic, and compliance is a snapshot, not a risk decision. C. ✅ Correct. Secure sponsorship and budget first. The business case gives leadership the information to fund the assessment, making everything downstream legitimate. D. Retroactive documentation is accepting the status quo and papering over it. Controls without risk linkage may be over-spent, under-scoped, or pointed at threats that no longer exist, and now that gap has your signature on it. Think like a manager: The CISO doesn't overrule the business; the CISO informs it. When leadership is the obstacle, persuasion is the first control you deploy.