Best control, measure and report
This paper presents an overview of the recommended approach for Boards when dealing with cyber risk, and of good starting points for Board cyber metrics. It is a complementary paper to the foregoing one addressed to Chief Information Security Officers (CISOs) on how to best control, measure and report cyber risks to their Boards and should be read in conjunction with that paper.
Facilitate proper oversight
This paper presents actionable guidance for CISOs to report cyber risk and its context to their senior stakeholders, such as their Board. It describes methods that help CISOs engage in cyber risk management, communicate this effectively, and facilitate proper oversight. It is the outcome of a group of seasoned practitioners sharing their best practices in a CISO Metrics Working Group.