Certified Information Security Manager (CISM)Information Security GovernanceMedium
An organization is considering a significant investment in a new cloud-based data analytics platform. The CISO is asked to present the information security implications to the executive committee. Which of the following should be the CISO's PRIMARY focus in this presentation?
- AAlignment of the platform's security posture with organizational risk appetite and regulatory obligations.
- BDetailed technical architecture of the proposed cloud platform and security controls.
- CPotential cost savings and return on investment (ROI) from the new platform.
- DA comprehensive list of all potential cyber threats targeting cloud platforms.
Show answer & explanationAnswer & explanation
Correct answer: A. Alignment of the platform's security posture with organizational risk appetite and regulatory obligations.
When presenting to an executive committee, the CISO's primary focus should be on how the new platform's security posture aligns with the organization's overall risk appetite and regulatory obligations. This translates technical security concerns into business-relevant language for decision-makers.
Why the other options are wrong
- B. Technical details are too granular for an executive committee; they need the business impact.
- C. Cost savings and ROI are important, but these are typically championed by other departments like finance or operations, not the CISO's primary security focus.
- D. A comprehensive list of threats is too technical and overwhelming for an executive committee without context of their impact on the organization's risk profile.
Executive Security Reporting
Communicating information security status, risks, and strategic alignment to executive leadership and the board of directors in business-centric, non-technical terms.
- Focus on business impact, not technical details.
- Relate security to risk appetite, compliance, and strategic goals.
- Enable informed decision-making at the highest level.
Memory trick: Executives care about risk, rules, and the bottom line, not just bytes and firewalls.