A newly appointed CISM is reviewing the organization's information security governance structure. Which of the following BEST demonstrates effective governance?
-
A
Security decisions are made exclusively by the IT department
-
B
The board of directors receives regular security risk reports
-
C
Security policies are updated only after a breach occurs
-
D
The CISO manages all security activities without oversight