CISO as the Driver of an ISMS Project in Public Administrations: Role, Tasks, and Localization of the CISO
摘要
The Information Security Officer (CISO) is increasingly playing a key role in combating the ever-increasing threats from cyberspace. In doing so, he must cover a wide range of activities and responsibilities, such as defining and monitoring a cybersecurity strategy, creating a security-oriented organizational culture, training employees to become more security-aware, and implementing security measures. This requires close cooperation with the IT management (CTO), the data protection officer (DPO), and the organizational management (CEO). In many local governments, the role of the CISO is occupied. But in contrast to the DPO, which has been established in the organizational hierarchy for a long time due to legal requirements, the CISO is often not located at the upper hierarchical level, but often in the line organization, or the task is performed by external third parties. This article compares the role tasks and positioning of the CISO in companies with administrations. In addition, he examines the positioning of the CISO in administrations of different sizes based on a study carried out. Based on the literature, he describes the tasks of the CISO and provides arguments for the optimal location of the CISO in the hierarchy of the administration so that cybercrime can be effectively combated.