Many times a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture. What would be the BEST choice of security metrics to present to the BOD?
To have accurate and effective information security policies how often should the CISO review the organization policies?
A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?
Which of the following is used to establish and maintain a framework to provide assurance that information security strategies are aligned with organizational objectives?