Question: Assume you are the CISO for a large cybersecurity program and your Board of Directors is asking how the capabilities in your program map to
Assume you are the CISO for a large cybersecurity program and your Board of Directors is asking how the capabilities in your program map to the capabilities listed in the NIST CSF framework. What methods would you use to communicate your answer to the Board, that is, how would you show them the current status of your companies program? After a few initial discussion posts, I will reply with how we are answering this question at my company.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
