Question
What stays with us?
Answer
Overall responsibility for information security, decisions on risk, approvals, and the operational implementation of measures stay with you. You appoint an internal contact, the information security coordinator, who organizes input and makes sure recommendations get addressed in your organization. Your external CISO sets the direction and checks whether the measures work.