While CISOs should administratively report to the CIO to facilitate resource allocation, better technical insight, strategic alliance etc. but should only be answerable for key picks, results and recommendations to the Board
Like