A CISM is presenting the security program's value to executive leadership. Which approach is MOST effective?
-
A
Detail the technical vulnerabilities remediated during the year
-
B
Present security metrics tied to business risk reduction and outcomes
-
C
Show the number of security incidents prevented by controls
-
D
Provide a list of all compliance requirements met