Chief Information Security Officer
nounid
1809·updated May 9, 2026verified
The person in charge of information security within the enterprise
MWE
Attested in
No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.
Classifications
Entity Type
Role90%rule-basedr:entity.role.named.v1
Sensitivity
Regulated85%rule-basedr:sens.regulated.framework.v1
Information Class
unclassified
Variants
- acronym
- CISO
- synonym
- senior manager with adequate security knowledge to be responsible for the vendor's Information Security Management
- plural
- Chief Information Security Officers
- possessive
- Chief Information Security Officer's
- pluralpossessive
- Chief Information Security Officers'
Framework definitions
- §1
- The person in charge of information security within the enterprise
- §1
- The person in an organization responsible for: • Developing and implementing an information system security training and orientation program in accordance with FISMA requirements; • Developing, evaluating and providing information about the CMS Information Security (IS) Program, and communicating CMS IS Program requirements and concerns to CMS management and personnel; • Ensuring that System Security Plans (SSPs) are developed, reviewed, implemented, and revised; • Maintaining documentation used to establish systems security level designations for all SSPs within CMS; • Ensuring that IS Risk Assessments (RAs) are developed, reviewed, and implemented for the SSP process; • Providing leadership & participating in IS incident response and reporting IS incidents in accordance with reporting procedures developed and implemented by Federal mandates, DHHS, and CMS; • Mediating and resolving systems security issues that arise between two CMS organizations, CMS and other federal organizations, or CMS and States or contractors; • Assuring that CMS business Component Information System Security Officers (ISSOs) are appointed and trained; • Assisting CMS business Component ISSOs in developing local systems security; and • Researching state-of-the-art systems security technology and disseminating information material in a timely fashion.
- §1 · legacy_primary
- The person in charge of information security within the enterpriseDR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
No incoming triples
No other term currently asserts a relationship to this one.