Objective:
Recommended Control 1:
The Chief Information Security Officer (CISO) sets the strategic
direction for information security within their agency
Agencies should appoint a person to the role of CISO or have the
role undertaken by an existing person within the agency
Recommended Control 2:
The CISO role should be undertaken by a member of the Senior
Executive Team or an equivalent management position
Recommended Control 3:
Where the role of the CISO is outsourced, potential conflicts of
interest in availability, response times or working with vendors
should be identified and carefully managed
Recommended Control 4:
CISO should report directly to the agency head on matters of
information security within the agency
Recommended Control 5:
CISO should develop and maintain a comprehensive strategic level
information security and security risk management program within
the agency aimed at protecting the agency’s information
Recommended Control 6:
CISO should be responsible for the development of an information
security communications plan
Recommended Control 7:
CISO should create and facilitate the agency security risk
management process
Recommended Control 8:
CISO should be responsible for ensuring compliance with the
information security policies and standards within the agency
Recommended Control 9:
CISO should be responsible for ensuring agency compliance with
the GOBISM through facilitating a continuous program of
certification and accreditation based on security risk management
Recommended Control 10:
CISO should be responsible for the implementation of information
security measurement metrics and key performance indicators
within the agency
Recommended Control 11:
CISO should provide strategic level guidance for agency ICT
projects and operations
Recommended Control 12:
CISO should coordinate the use of external information security
resources to the agency including contracting and managing the
resources
Recommended Control 13:
CISO should be responsible for controlling the information security
13