A multinational organization has completed a security control assessment across multiple facilities and identified that 85% of their technical controls are operating effectively. However, they also discovered that administrative controls have a significantly lower effectiveness rate of 65%. The Chief Information Security Officer (CISO) wants to present these findings to the board of directors to secure additional budget for security improvements. What should be the primary focus of the CISO's presentation to best justify the budget request?
Comparing the organization's control effectiveness rates against industry benchmarks
Highlighting potential compliance violations resulting from the ineffective controls
Presenting a detailed analysis of each failed control and its technical implications
Quantifying the potential business impact of the identified control deficiencies
The CISO should focus on the risk exposure resulting from the control gaps rather than just presenting the raw effectiveness percentages. While technical details and compliance status are important, board members are ultimately concerned with business risk and potential financial impact. By quantifying the potential business impact of the control deficiencies, the CISO translates technical findings into business language that resonates with the board's priorities. This approach connects security control weaknesses to business outcomes and provides clear justification for additional investment. Boards typically make decisions based on risk to business operations and financial considerations, not on technical metrics or compliance requirements alone.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is quantifying business impact important in a CISO's presentation?
Open an interactive chat with Bash
What are administrative controls, and why might their effectiveness be lower than technical controls?
Open an interactive chat with Bash
How can industry benchmarks help in security assessments if they aren't the primary focus for the board?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .