Leadership outside of the CISO organization often lacks knowledge on how to measure the required investment for cloud security controls. Security and risk management leaders must speak their language using outcome-driven metrics (ODMs) to help leaders balance protection levels with budget priorities.
Security and risk management leaders responsible for cloud security should use this research to:
- Establish automated visibility to the cloud properties (IaaS, PaaS and SaaS) in use at their organization.
- Translate business context into security investments in cloud security.
- Provide executives and business leaders visibility into the cloud security program.
- Review metrics while adding cloud security capabilities to identify and reflect the investment purpose.