Protective Security Policy Framework (PSPF) Release 2026
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0012: 0012 CISO capability, experience and NV1 clearance

Requirement 0012 (Part One: Governance, section 2.3 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 31 October 2024; retained from Release 2025): The Chief Information Security Officer has the appropriate capability and experience and holds a minimum security clearance of Negative Vetting 1. The CISO needs the capability, leadership experience and technical skills to make informed cyber decisions and holds at least NV1.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.