‹ GR-12.2.11 GR-12.2.13 › GR-12.2.12 Licensees must ensure that the cyber security risk management function is headed by suitably qualified Chief Information Security Officer (CISO), with appropriate authority to implement the Cyber Security strategy. Added: January 2022 ‹ GR-12.2.11 GR-12.2.13 ›