Las entidades esenciales garantizarán que el responsable de la seguridad de la información cumpla los siguientes requisitos:
a) Contar con personal con conocimientos especializados y experiencia en materia de ciberseguridad, desde los puntos de vista jurídico, organizativo y técnico, adecuados al desempeño de sus funciones.
b) Contar con los recursos necesarios para el desarrollo de sus funciones.
c) Ostentar una posición en la organización que facilite el desarrollo de sus funciones, participando de forma adecuada y en todas las cuestiones relativas a la seguridad, y manteniendo una comunicación real y efectiva con el consejo de administración.
d) Mantener la debida independencia respecto de los responsables de las redes y los sistemas de información.
Organizations are required to assign responsibility for information security to a specific person, a dedicated team, or a committee. This designated individual or group will serve as the main point of contact and will handle all technical communication and coordination with supervisory authorities and the national Computer Security Incident Response Teams (CSIRTs).
If the responsibility is given to a team or committee rather than a single person, it is necessary to appoint one individual as the official representative. Additionally, a backup person should be assigned to take over these duties whenever the primary representative is unavailable due to absence, vacancy, or illness. This ensures that there is always someone accountable and able to respond promptly to security matters.
The organization must inform the relevant supervisory authorities when they appoint an Information Security Officer. This notification must be made within three months after the appointment is made. If there are any later changes, such as a new appointment or the termination (resignation, dismissal, etc.) of the current Information Security Officer, these changes must be reported within one month of when they happen.
The organization shall ensure that the information security officer has the necessary resources (e.g., budget, personnel, tools, time) to effectively carry out their duties. The officer's position within the organization should facilitate their work, ensuring appropriate participation in all relevant security matters. Furthermore, a direct and effective communication channel with the board of directors or top management should be established and maintained to ensure strategic alignment and oversight of cyber security. The information security officer should also operate with due independence from those responsible for the technical implementation and management of networks and information systems, avoiding conflicts of interest.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.