A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this?
-
A
Delegating all security decisions to the CISO
-
B
Establishing a board-level cybersecurity committee with executive oversight
-
C
Requiring IT to report risks only during annual audits
-
D
Outsourcing risk management to a third-party vendor