An IT risk manager is preparing a quarterly risk report for the CISO. Which type of reporting structure does this represent?
Trap 1: Executive risk reporting
Not a standard ISACA term; tactical is correct.
Trap 2: Operational risk reporting
Operational reporting is weekly/monthly to IT management.
Trap 3: Strategic risk reporting
Strategic reporting is semi-annual/annual to the board.
- A
Tactical risk reporting
Tactical risk reporting targets senior management such as the CISO, translating risk into business-unit and control-level detail over a quarterly cycle. Strategic reporting serves the board, while operational reporting serves process owners, so tactical matches the CISO audience and quarterly cadence.
- B
Executive risk reporting
Why it fails: Not a standard ISACA term; tactical is correct.
- C
Operational risk reporting
Why it fails: Operational reporting is weekly/monthly to IT management.
- D
Strategic risk reporting
Why it fails: Strategic reporting is semi-annual/annual to the board.