Established Security Program & Executive Governance
- A dedicated cybersecurity function led by an accountable CISO operates under a documented program charter aligned to the NIST Cybersecurity Framework.
- Cybersecurity risk is governed through a recurring executive reporting cadence covering objectives, projects, threats, training, and incidents.
- A formal IT portfolio-governance process provides regular project status reporting to executive leadership.
Framework Alignment: NIST CSF GV.OC, GV.RM, GV.OV; SOC 1 Type II; GDPR Art. 24, 5(2); ISO 27001:2022 A.5.1, A.5.2