An organization should appoint a Security Protection Manager, responsible for managing and coordinating security protection activities. The officer's position, responsibilities, and authority must be formally defined and documented.
The role description should specify that the Security Protection Officer:
- Leads and coordinates the organization's security protection work.
- Verifies that operations are conducted in accordance with the Security Protection Act and related regulations.
- Reports directly to the head of the business or, if one does not exist, to the organization's management board.
It should also be documented that this overall responsibility cannot be delegated to another person.