Which of the following BEST illustrates an effective security governance reporting structure?
-
A
CISO reports to the CTO only
-
B
Security reports are shared only within the IT department
-
C
CISO reports to both the CEO and board with regular updates
-
D
Security metrics are reported only after incidents occur