GlossaryCompliance operations

CISO

Short answer

The CISO (Chief Information Security Officer) is the senior leader responsible for an organisation's information security strategy, risk management and security programme. The role connects technical security with business decisions and reports to executive management or the board.

Responsibilities

A CISO defines the security strategy and budget, owns the policies and the risk assessment, oversees compliance with frameworks such as ISO 27001 or the ENS, leads the response to serious incidents and reports to management on risk in business terms. In larger companies the CISO leads a team; in smaller ones, the role is often combined with IT or covered externally.

Reporting line

Reporting to the CEO or the board, rather than to the head of IT, helps avoid conflicts between delivery speed and security. In the ENS, the security officer (responsable de seguridad) must be a different person from the system officer (responsable del sistema), for the same reason.

Why the role is gaining weight

NIS2 makes management bodies approve cybersecurity measures, oversee them and receive training, and they can be held liable for failures. DORA puts ultimate responsibility for ICT risk on the management body of financial entities. Both increase the need for someone who can advise management with authority.

When there is no CISO

Many small and mid sized companies cannot justify a full time CISO. A vCISO covers the same responsibilities part time or as a service, so that someone is still in charge of security and answers to management.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub