‹ RM-3.1.7 RM-3.1.9 › RM-3.1.8 Licensees must ensure that the cyber security risk management function is headed by suitably qualified Chief Information Security Officer (CISO), with appropriate authority to implement the Cyber Security strategy. Added: January 2022 ‹ RM-3.1.7 RM-3.1.9 ›