With its latest update to the FAQs, Italy's National Cybersecurity Agency (ACN) has clarified a principle that is set to have a direct impact on the governance of NIS entities: strategic responsibility for cybersecurity rests with the management body.
The guidance confirms that approval of the documentation required under the NIS 2 framework cannot be delegated, while distinguishing the role of the board, responsible for setting strategic direction and exercising oversight, from that of the technical functions, which are responsible for operational management and maintaining the required documentation.
"*" indicates required fields
THIS WEBSITE IS ECO-SUSTAINABLE AND REDUCES THE IMPACT OF CO2 IN THE ATMOSPHERE
Here’s an estimate of our emissions in real time