unified
UC-GOV-09 — Appoint accountable security leadership (CISO)
Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-09
- title
- Appoint accountable security leadership (CISO)
- statement
- Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-29
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.4
- coverage
- partial
- delta
- 500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-09 — Appoint accountable security leadership (CISO) mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Accountable security leadership with authority and resources strengthens the control environment.
- UC-GOV-09 — Appoint accountable security leadership (CISO) maps_to 500.4 — Chief Information Security Officer (CISO)
- framework
- nydfs-500
- control_id
- 500.4
- coverage
- partial
- delta
- 500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Information Security Program Governance Review operates UC-GOV-09 — Appoint accountable security leadership (CISO)
- Security Control Assessment & POA&M Remediation tests UC-GOV-09 — Appoint accountable security leadership (CISO)
- UC-GOV-09 — Appoint accountable security leadership (CISO) maps_to PM-2 — Information Security Program Leadership Role
- framework
- nist-800-53
- control_id
- PM-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-09 — Appoint accountable security leadership (CISO) maps_to PM-29 — Risk Management Program Leadership Roles
- framework
- nist-800-53
- control_id
- PM-29
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-09 — Appoint accountable security leadership (CISO) mitigates Innovation and R&D governance failure
- strength
- related
- rationale
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-09 — Appoint accountable security leadership (CISO)