Glossary
CISO
Chief Information Security Officer: the professional in charge of defining and steering an organisation's cybersecurity policy, a central player in NIS 2 compliance.
The CISO (Chief Information Security Officer) drives an organisation's cybersecurity strategy. They are the primary point of contact with the authorities under NIS 2.
Role under NIS 2
NIS 2 does not formally require the appointment of a CISO, but it does require the management body to oversee and approve cyber risk-management measures. In practice, the CISO is the operational guarantor of compliance.
Typical responsibilities
- Developing and maintaining the Information Security Policy (ISP)
- Conducting risk analysis and defining the risk treatment plan
- Coordinating incident response and regulatory notifications
- Steering audits and security testing
- Driving staff awareness and training
- Acting as the point of contact with ANSSI and competent authorities
Profile and skills
A CISO combines technical skills (information security, networks, cryptography) with managerial ones (project management, communication, legal). Certifications such as CISSP, CISM or ISO 27001 Lead Implementer are well recognised in the profession.