Objective: The Chief Information Security Officer (CISO) sets the strategic direction for information security within their agency budget Recommended Control 14: CISO should be fully aware of all information security incidents within the agency Recommended Control 15: CISO should coordinate the development of disaster recovery policies and standards within the agency to ensure that business‐ critical services are supported appropriately and that information security is maintained in the event of a disaster Recommended Control 16: CISO should be responsible for overseeing the development and operation of information security awareness and training programs within the agency The requirement to appoint a member of the Senior Executive Team or an equivalent management position to the role of CISO does not require a new dedicated position be created in each agency. Where multiple roles are held by the CISO (manager of business unit), potential conflicts of interest should be clearly identified and a mechanism implemented to allow independent decision making in areas where conflict may occur. Particular attention shall be paid to operational imperatives and security requirements conflict. The CISO within an agency is responsible for facilitating communications between security personnel, ICT personnel and business personnel to ensure alignment of business and security objectives within the agency. The CISO is also responsible for providing strategic level guidance for the agency security program and ensuring compliance with national policy, standards, regulations and legislation. Having the CISO coordinate the use of external information security resources will ensure that a consistent approach is being applied across the agency. As the CISO is responsible for the overall management of information security within an agency, it is important that they report directly to the agency head on any information security issues. To ensure that the CISO is able to accurately report to the agency head on information security issues within their agency it is important that they remain fully aware of all information security incidents within their agency. 14

Select target paragraph3