Objective: Recommended Control 1: The Chief Information Security Officer (CISO) sets the strategic direction for information security within their agency Agencies should appoint a person to the role of CISO or have the role undertaken by an existing person within the agency Recommended Control 2: The CISO role should be undertaken by a member of the Senior Executive Team or an equivalent management position Recommended Control 3: Where the role of the CISO is outsourced, potential conflicts of interest in availability, response times or working with vendors should be identified and carefully managed Recommended Control 4: CISO should report directly to the agency head on matters of information security within the agency Recommended Control 5: CISO should develop and maintain a comprehensive strategic level information security and security risk management program within the agency aimed at protecting the agency’s information Recommended Control 6: CISO should be responsible for the development of an information security communications plan Recommended Control 7: CISO should create and facilitate the agency security risk management process Recommended Control 8: CISO should be responsible for ensuring compliance with the information security policies and standards within the agency Recommended Control 9: CISO should be responsible for ensuring agency compliance with the GOBISM through facilitating a continuous program of certification and accreditation based on security risk management Recommended Control 10: CISO should be responsible for the implementation of information security measurement metrics and key performance indicators within the agency Recommended Control 11: CISO should provide strategic level guidance for agency ICT projects and operations Recommended Control 12: CISO should coordinate the use of external information security resources to the agency including contracting and managing the resources Recommended Control 13: CISO should be responsible for controlling the information security 13

Select target paragraph3