CISO

Chief Information Security Officer.
Official responsible for carrying out the Chief Information Officer responsibilities under the Federal Information Security Management Act (FISMA) and serving as the Chief Information Officer’s primary liaison to the agency’s authorizing officials, information system owners, and information systems security officers.
Note 1: With respect to SecCM, a Senior Agency Information Security Officer is an individual that provides organization-wide procedures and/or templates for SecCM, manages or participates in the Configuration Control Board, and/or provides technical staff for security impact analyses.
Note 2: Organizations subordinate to federal agencies may use the term Senior Information Security Officer or Chief Information Security Officer to denote individuals filling positions with similar responsibilities to Senior Agency Information Security Officers.
See NIST SP 800-128 under Senior Agency Information Security Officer (44 U.S.C., Sec. 3544) for more information.
See the following under Chief Information Security Officer for more information:
FIPS 200
NIST SP 800-137
NIST SP 800-30 Rev. 1
NIST SP 800-37 Rev. 1
NIST SP 800-39
NIST SP 800-53 Rev. 4
NIST SP 800-53A Rev. 4
Official responsible for carrying out the Chief Information Officer responsibilities under FISMA and serving as the Chief Information Officer’s primary liaison to the agency’s authorizing officials, information system owners, and information system security officers.
See the following under Senior Agency Information Security Officer for more information:
NIST SP 800-18 Rev. 1 (44 U.S.C., Sec. 3544).
NIST SP 800-60 Vol. 1 Rev. 1.
NIST SP 800-60 Vol. 2 Rev. 1.
See senior agency information security officer (SAISO).
See CNSSI 4009-2015 (FIPS 200) for more information.