A CISO is preparing the quarterly management review pack for the executive risk committee. The security operations team has produced a 40-page dashboard of raw metrics, including ticket volumes, scan findings, patch counts, and training completion rates. The committee has 30 minutes and has previously complained that prior packs were operational rather than strategic. What should the CISO do FIRST to make the pack fit for purpose?
- AAdd benchmark comparisons against industry peers for every operational metric currently in the pack.
- BReduce the pack to a single executive summary slide that lists the top five security incidents from the quarter.
- CSchedule a longer review slot with the executive committee so the existing 40-page pack can be presented in full.
- DConvert the raw operational metrics into a small set of KRIs and KPIs mapped to the organisation's risk appetite, with thresholds and trends. Correct
Why A is wrong: Peer benchmarking is useful supporting context but does nothing to address the core problem that the pack is operational rather than tied to the organisation's risk appetite, so it is a secondary improvement at best.
Why B is wrong: An incident summary is reactive and narrow; management review requires forward-looking risk indicators, control effectiveness data, and trend analysis, not just a list of what went wrong last quarter.
Why C is wrong: Expanding the time slot accommodates the existing flawed format rather than fixing it; the issue is the level of abstraction of the data, not the volume of time, and executive attention is a scarce resource that should not be wasted on operational detail.
Why D is correct: Management review packs at executive level should present risk-tied indicators with thresholds and trend direction so the committee can make governance decisions; this converts operational data into the strategic signals they actually need.