Responsibility for the cybersecurity program is assigned to a role with sufficient authority
Context and Guidance: It’s important that the role that is made responsible for executing the cybersecurity program (such as a chief information security officer) has the necessary and sufficient authority within the organisation to carry out program activities and to obtain the necessary resources to support the program.
Related Practices • Input From: Implementing PROGRAM-2b provides input that may be useful for implementing this practice.