The organization must designate a person responsible for the security of electronic information systems. This person's responsibilities should include:
- operating the risk management framework,
- reporting cybersecurity incidents and
- maintaining contact with the national cybersecurity incident response center.
The agreement should clearly define these responsibilities if an external person or entity is contracted to perform these tasks. The designated person, whether internal or external, should possess the necessary qualifications and experience for the role. Any legally required background checks, such as verifying full legal capacity and absence of a criminal record, should be conducted.
The organisation should ensure that the person responsible for the security of electronic information systems is provided with the necessary conditions to perform their duties. This involves ensuring that the person:
- participates in the preparation of all decisions affecting the protection of electronic information systems.
- has the necessary authorisations, information, and resources to ensure the protection of the information system.
- has access to all systems, data, and information necessary for the performance of their tasks.