unified

UC-GOV-09 — Appoint accountable security leadership (CISO)

Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-09
title
Appoint accountable security leadership (CISO)
statement
Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    PM-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    PM-29
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.4
    coverage
    partial
    delta
    500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections