Before a quarterly meeting, the CISO must brief the municipal audit committee on top cyber risks, treatment status, and trend indicators. Which activity is required?
Select an answer to reveal the explanation.
Short Explanation
Governance folks need a clear dashboard, not a surprise party. Risk reporting packages what's hot, who's owning it, and which way the arrows are pointing so the audit committee can steer.
Full Explanation
Risk reporting communicates identified risks, owners, treatments, thresholds, and KRIs to stakeholders such as an audit committee. Transparent packaging of posture supports oversight decisions. Suppressing the register or substituting unrelated metrics undermines governance and is not an acceptable reporting practice.