Cybersecurity Officer
Services
Eight services covering the role, from scoping to mentoring.
Service sheet
Service catalogue
Each service has its own sheet, with deliverables, method and regulatory basis.
| Code | Service | Type | Who it is for | Format |
|---|---|---|---|---|
| CSO-01 | External or Supporting Cybersecurity Officer | Recurring service | Covered entities and international groups | Performing or supporting the role, with an annual plan and reporting |
| CSO-02 | Assessment of Scope under the Act | Assessment | Organisations unsure whether they are covered | Criteria analysis and a scoping opinion |
| CSO-03 | Risk Management Measures Programme | Project | Covered entities that must demonstrate measures | Plan by area of measures, with evidence |
| CSO-04 | Notification Readiness and Coordination | Project | Cybersecurity officers and response teams | Deadline matrix, playbook and exercise |
| CSO-05 | Governance and Management Bodies | Project and training | Boards, executive teams and councils | Governance model and executive session |
| CSO-06 | Product and Digital Supply Chain Security | Project | Manufacturers of products with digital elements and their buyers | Product review, contracts and reporting duties |
| CSO-07 | Exercises, Simulations and Team Capability | Training | Response, management and communication teams | Tabletop exercise or technical simulation |
| CSO-08 | Career Path and Mentoring | Mentoring | Professionals appointed to the role | Monthly sessions and an individual plan |
At a glance
External or Supporting Cybersecurity Officer
External performance of the cybersecurity role, or support to the designated officer, with an annual plan, evidence and reporting to the management body.
Open service sheet CSO-02Assessment of Scope under the Act
A reasoned determination of how the entity qualifies and of the resulting obligations, considering sector, size and services provided.
Open service sheet CSO-03Risk Management Measures Programme
Design and follow-up of the technical, operational and organisational measures required from covered entities, with evidence for each area.
Open service sheet CSO-04Notification Readiness and Coordination
Preparation of the incident communication sequence, from the early warning to the final report, with the legal deadlines and the parallel recipients.
Open service sheet CSO-05Governance and Management Bodies
Definition of the cybersecurity governance model and training of the management body on its own responsibilities.
Open service sheet CSO-06Product and Digital Supply Chain Security
Analysis of the duties applicable to products with digital elements and of the security requirements to impose on, and meet within, the supply chain.
Open service sheet CSO-07Exercises, Simulations and Team Capability
Design and delivery of exercises that test decision-making, communication and deadlines, with a lessons-learnt report.
Open service sheet CSO-08Career Path and Mentoring
Individual support for the person holding the role, with a competence plan, review of real cases and preparation for dealing with the authority.
Open service sheetAn appointed role is not yet a role performed
Start by checking your organisation scope or ask for a proposal to structure the role.