The Chief Information Security Officer (CISO) receives a quarterly report that includes a risk heat map and trend analysis of top risks. This type of reporting is best described as:
Tactical reporting is quarterly and aimed at CISO/CIO, covering heat maps and trends.
Why this answer
Tactical risk reporting is typically provided to senior IT management (CISO/CIO) on a quarterly basis and includes risk heat maps and trend analyses.