Which governance structure element is MOST important for ensuring effective cyber risk oversight at the board level?
-
A
Requiring the CISO to hold a CISSP certification
-
B
Establishing a board-level committee with defined cyber risk responsibilities and regular reporting cadence
-
C
Mandating that all board members complete annual cybersecurity training
-
D
Ensuring the IT department reports directly to the board chair