Chief Information Security Officer
A Chief Information Security Officer (CISO) is a senior executive who oversees an organization's information, cyber, and technology security. The role typically involves establishing and maintaining the organization's security program to protect its information and systems. In many U.S. federal contexts under FISMA, a related official carries out certain Chief Information Officer security responsibilities and serves as the CIO's primary liaison.
The CISO is a senior-level executive responsible for establishing, implementing, and maintaining an enterprise information security program, with oversight of information, cyber, and technology security functions. In U.S. federal usage as reflected in NIST terminology, an information security official is designated to carry out the Chief Information Officer's security responsibilities under FISMA and to serve as the CIO's primary liaison, which may differ from private-sector titling and reporting structures. The scope, reporting lines, and precise mandate of the CISO vary by organization and jurisdiction; this entry describes the role generally and does not, based on the evidence provided, define its specific relationship to AI governance or model risk management functions, which may be assigned separately or in coordination with the CISO depending on the organization.
Why it matters
The Chief Information Security Officer occupies a senior accountability position for how an organization protects its information, cyber, and technology assets. As AI systems become embedded in enterprise operations, the security surface these systems introduce—training data confidentiality, model access controls, and the integrity of automated decision pipelines—frequently intersects with the CISO's existing mandate. Understanding where that mandate begins and ends matters because AI governance and model risk management responsibilities may sit with the CISO, may be assigned to separate functions, or may be shared, depending on how an organization structures accountability.
Who it's relevant to
Inside CISO
Common questions
Answers to the questions practitioners most commonly ask about CISO.