4 Questions the Board must ask its CISO are designed to allow a board to understand if the organization is secure and also compare their cybersecurity posture with other companies. CISOs should be encouraged to explain an information security program in terms of business-aligned processes, rather than complex technology. The board has to make sure that the scope of a risk assessment methodology is holistic. And there is a good chance that the board is already familiar with security in line with their “iduciary responsibility” The board should return on return on investment needed to return on cybersecurity.”]
Source: https://www.inforisktoday.com/blogs/4-questions-board-must-ask-its-ciso-p-2218

