‹ OM-5.5.7 OM-5.5.9 › OM-5.5.8 The Board must ensure that the cyber security risk management function is headed by suitably qualified Chief Information Security Officer (CISO), with appropriate authority to implement the Cyber Security strategy. Added: July 2021 ‹ OM-5.5.7 OM-5.5.9 ›