Protective Security Policy Framework (PSPF) Release 2026
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0013: 0013 CISO accountable for cyber security risk

Requirement 0013 (Part One: Governance, section 2.3 Entity Protective Security Roles and Responsibilities; applies to All entities; dated 01 July 2025; retained from Release 2025): The Chief Information Security Officer is accountable to the Accountable Authority for cyber security risks and how the entity's cyber security program is managing these risks. From 1 July 2025 the CISO is accountable to the Accountable Authority for cyber risks and how the program manages them, working closely with the CSO so cyber is not siloed.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.