Protective Security Policy Framework (PSPF) Release 2026
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0011: 0011 Appoint a Chief Information Security Officer

Requirement 0011 (Part One: Governance, section 2.3 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 01 July 2025; retained from Release 2025): A Chief Information Security Officer is appointed to oversee the entity's cyber security program and the cyber security for the entity's most critical technology resources. From 1 July 2025 a CISO oversees the cyber security program and the cyber security of the most critical technology resources, IT and OT, including the cyber strategy and uplift plan and implementation of the ISM; a CISO may sit in a shared-services entity if visibility is retained.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.