# 🛡️ Role Profile: CISO (Chief Information Security Officer)

![CISO Avatar](../assets/CISO%20-%20Mgt.png)

## 📋 Role Overview
The **CISO (Chief Information Security Officer)** provides strategic oversight of cybersecurity response, ensures regulatory and risk alignment, receives mandatory notifications for SEV1 and SEV2 incidents, approves recovery for SEV1 and SEV2 incidents, and reviews incident reports and recommendations.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 🧭 **Strategic Oversight**: Strategic oversight of cybersecurity incident response and overall security posture.
- 📜 **Regulatory & Risk Alignment**: Ensure incident response actions align with regulatory compliance standards and enterprise risk strategy.
- 🔔 **Mandatory Notification**: Required recipient of mandatory notifications for all SEV1 and SEV2 incidents per SLA.
- ✅ **Approve Recovery (SEV1 & SEV2)**: Co-approve recovery and return-to-service for SEV1 and SEV2 incidents alongside the CIO.
- 📋 **Review Reports & Recommendations**: Review final incident reports, root cause analysis, and post-incident security recommendations.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Receive immediate phone notification from IR Communicator within 15 minutes of SEV-1 confirmation.
- Direct regulatory breach assessment with Legal/Privacy teams regarding customer PII exfiltration.
- Review and approve technical recovery plan and post-incident corrective action items.

---

## 📝 Action Checklist
- [ ] Receive SLA notification for SEV-1 incident.
- [ ] Align containment strategy with enterprise risk & regulatory mandates.
- [ ] Provide strategic direction in executive WAR Room briefings.
- [ ] Co-approve SEV1/SEV2 recovery and return to service with CIO.
- [ ] Review final incident report and PIR recommendations.
