712-50 Question 32
Single answerCreate risk reporting metrics and processesA newly appointed CISO reports cyber risk quarterly to the board of a global manufacturing company. The board has complained that the current report is too technical, focuses on vulnerability counts, and does not help them decide where to invest. At the same time, business unit leaders want more operational detail so they can track remediation progress. The CISO has been asked to redesign the risk reporting process so it supports both governance decisions and operational accountability. Which approach is the MOST effective?
- A
Create a single enterprise security dashboard centered on raw metrics such as total vulnerabilities, patching backlog, and number of security alerts so all stakeholders work from the same detailed view.
- B
Develop a tiered reporting process with board-level key risk indicators tied to business impact and risk appetite, supported by management-level metrics that show remediation status, trend lines, ownership, and exception handling.
- C
Report only on the organization’s top 10 current risks each quarter and remove all historical trend information to keep the board focused on the present risk landscape.
- D
Provide separate reports for each business unit based primarily on technical control performance, and allow each unit to define its own risk scoring method to increase local relevance.
Show answer and explanation
Correct answer: B
Explanation
The most effective approach is to design a tiered risk reporting process that maps operational data to executive decision needs. In practice, this means distinguishing between metrics for governance and metrics for operations. Boards and executive committees generally need summarized indicators such as top risks by business impact, risk trends, control gaps affecting strategic objectives, threshold breaches relative to risk appetite, and the status of major remediation initiatives. Operational leaders need more detailed measures such as open remediation actions, overdue exceptions, asset coverage, control maturity changes, and progress against agreed plans. Best practices from governance and risk frameworks such as NIST Cybersecurity Framework, NIST SP 800-55 for performance measurement, ISO/IEC 27005 for information security risk management, and COBIT emphasize that metrics should be aligned to stakeholder needs, risk tolerance, decision-making responsibilities, and accountability. Effective reporting processes also include standard definitions, consistent scoring criteria, reporting cadence, thresholds for escalation, ownership of remediation actions, and trend analysis over time. The key point is that good risk reporting is not just about collecting security metrics; it is about translating them into actionable business intelligence for each audience.
- A. Incorrect.
This is incorrect because a single detailed dashboard does not meet the needs of different audiences. Boards typically need concise, decision-oriented reporting that connects cyber risk to business impact, strategic objectives, and risk appetite rather than operational telemetry. Raw counts such as vulnerabilities or alerts can be useful for security operations, but without context they rarely support executive decisions on prioritization or investment. A common misconception is that one detailed report improves transparency for everyone, when in practice it often obscures decision-relevant information.
- B. Correct.
This is correct because effective risk reporting is audience-specific, decision-oriented, and aligned to governance objectives. Board reporting should use key risk indicators and summaries that show risk exposure in business terms, material trends, threshold breaches, and implications for strategy, investment, and risk appetite. Management reporting should be more granular, showing remediation progress, accountable owners, timelines, exceptions, and trend data needed to drive action. This approach also creates a repeatable process for escalation from operational metrics to executive risk reporting, which is consistent with established governance and risk management practices.
- C. Incorrect.
This is incorrect because removing historical trend information weakens decision-making. Trend data helps the board determine whether risk is improving, deteriorating, or remaining outside tolerance over time. Reporting only a top 10 list may be concise, but it can hide systemic issues, control effectiveness patterns, and whether remediation investments are working. The misconception here is that brevity alone makes reporting better; in reality, concise reporting still needs trend and threshold context.
- D. Incorrect.
This is incorrect because allowing each business unit to define its own risk scoring method undermines enterprise comparability, aggregation, and governance oversight. While local relevance matters, executive risk reporting requires a common taxonomy, scoring methodology, and escalation criteria so the CISO and board can compare exposures across the enterprise and prioritize consistently. Technical control performance alone also does not adequately express business risk. This option reflects the common error of confusing decentralized operational reporting with effective enterprise risk reporting.