Oversight (GV.OV)
Governance oversight deals with reviewing the overall cybersecurity and governance programs. Here, we’ll review key performance indicators (KPIs) or key metrics that are used to gauge the progress of the program and ensure that it’s on track to meet expectations. These indicators are then used to inform and update the program to ensure that it’s working effectively.
GV.OV-01
Throughout this chapter, we’ve discussed the need to collect metrics for how well the program is working. It’s in this control family that we review those metrics to ensure that the program is working as intended. Metrics will also promote the need for additional resources, if required, and also show where the program is lacking.
Where the program may be lacking, we’ll look for efficiencies to improve that part of the program. We could...