In my experience, c level folks just want someone who can produce a dashboard or executive report with a bunch of green check marks that basically say “yay! We’re secure”. They don’t care about the why, how, if the check marks are actually meaningful, etc. This mindset is then reinforced by vendors selling security snake oil - the entire infosec domain is a shit show; if infosec practitioners ever want to be taken seriously, they need to collectively get their shit together and organize around some real tangible standards.
There's the MITRE ATT&CK Framework https://attack.mitre.org/ which is gaining attention and seems very promising (although it of course isn't the golden answer to all questions, it goes a long way to cover the basics).