CISM - Certified Information Security Manager Practice Test
CISM Information Security Governance 3
Which of the following BEST illustrates an effective security governance reporting structure?
Select your answer
A
CISO reports to the CTO only
B
Security reports are shared only within the IT department
C
CISO reports to both the CEO and board with regular updates
D
Security metrics are reported only after incidents occur
Hint