Objective:
The Chief Information Security Officer (CISO) sets the strategic
direction for information security within their agency
budget
Recommended Control 14:
CISO should be fully aware of all information security incidents
within the agency
Recommended Control 15:
CISO should coordinate the development of disaster recovery
policies and standards within the agency to ensure that business‐
critical services are supported appropriately and that information
security is maintained in the event of a disaster
Recommended Control 16:
CISO should be responsible for overseeing the development and
operation of information security awareness and training programs
within the agency
The requirement to appoint a member of the Senior Executive Team or an equivalent management
position to the role of CISO does not require a new dedicated position be created in each agency.
Where multiple roles are held by the CISO (manager of business unit), potential conflicts of interest
should be clearly identified and a mechanism implemented to allow independent decision making
in areas where conflict may occur. Particular attention shall be paid to operational imperatives and
security requirements conflict.
The CISO within an agency is responsible for facilitating communications between security
personnel, ICT personnel and business personnel to ensure alignment of business and security
objectives within the agency. The CISO is also responsible for providing strategic level guidance for
the agency security program and ensuring compliance with national policy, standards, regulations
and legislation.
Having the CISO coordinate the use of external information security resources will ensure that a
consistent approach is being applied across the agency.
As the CISO is responsible for the overall management of information security within an agency, it is
important that they report directly to the agency head on any information security issues.
To ensure that the CISO is able to accurately report to the agency head on information security
issues within their agency it is important that they remain fully aware of all information security
incidents within their agency.
14