Learning Objectives:

  • Understand the appointment requirements for the Chief Information Security Officer (CISO).

  • Identify the key responsibilities of the CISO in a financial institution.

  • Recognise the CISO’s role in implementing and overseeing the cybersecurity programme.

  • Understand the relationship between the CISO and other governance functions.

3.1 Appointment and Qualification Requirements

The appointment of a qualified CISO is a regulatory requirement for financial institutions in many jurisdictions. The Central Bank of Nigeria’s Framework requires that a qualified individual is appointed as the CISO on the recommendation of Senior Management . The CISO shall be responsible for overseeing and implementing the bank’s cybersecurity programme .

In the case of banking Groups, while institutions may collaborate with the group CISO to ensure an effective enterprise-wide cybersecurity programme, a CISO shall be appointed in conformity with the regulatory requirements . This ensures that each entity has dedicated cybersecurity leadership.

The State Bank of Pakistan has established a Cyber Risk Officers Scheme (CROS) that focuses on the growing requirements associated with cyber risk and information technology governance in the financial sector . This reflects the importance of developing specialised expertise in cyber risk management.

3.2 The CISO’s Core Responsibilities

The CISO is responsible for implementing and overseeing the institution’s cybersecurity programme. The Central Bank of Nigeria’s Framework identifies the CISO’s role in overseeing and implementing the bank’s cybersecurity programme . The Central Bank of Eswatini’s Guidelines note that the institution’s cyber resilience framework should be supported by clearly defined roles and responsibilities, and it is incumbent upon management to create a culture that recognises that staff at all levels have important responsibilities in ensuring the institution’s cyber resilience .

The CISO’s responsibilities typically include:

  • Programme Management: Overseeing the implementation of the cybersecurity programme.

  • Policy Development: Developing and maintaining cybersecurity policies, procedures, and standards.

  • Risk Assessment: Conducting and overseeing cyber risk assessments.

  • Incident Management: Leading incident response and recovery efforts.

  • Reporting: Reporting on cybersecurity status to Senior Management and the Board.

  • Compliance: Ensuring compliance with regulatory requirements.

  • Training: Overseeing cybersecurity awareness and training programmes.

3.3 The CISO’s Role in Governance

The CISO plays a critical role in the cybersecurity governance structure. The Saudi Central Bank’s Cybersecurity Framework requires entities to develop a robust Cyber Security Governance structure that is supported with appropriate resources to oversee and control the overall approach to cyber security . The CISO is a key figure in this structure.

The CISO should be empowered with sufficient authority and resources to carry out their responsibilities effectively. This includes:

  • Access to Decision-Making: The CISO should have access to senior leadership and the board on cybersecurity matters.

  • Budget Authority: The CISO should have input into the cybersecurity budget and resource allocation.

  • Policy Authority: The CISO should have authority to develop and enforce cybersecurity policies.

  • Independence: The CISO should be independent of operational IT functions to ensure objective oversight.

3.4 Relationship with Other Governance Functions

The CISO does not operate in isolation; they must coordinate with other governance functions to ensure effective cybersecurity management. The Central Bank of Nigeria’s Framework requires that cybersecurity governance outlines the responsibilities of the Board of Directors, Senior Management, the CISO, and other relevant Risk Management Control functions .

Key relationships include:

  • Risk Management: The CISO should coordinate with the risk management function to ensure cyber risks are properly identified, assessed, and managed.

  • Compliance: The CISO should coordinate with the compliance function to ensure regulatory requirements are met.

  • Internal Audit: The CISO should coordinate with internal audit to ensure controls are tested and verified.

  • Human Resources: The CISO should coordinate with HR on security awareness training and insider threat management.