Chief Information Security Officer -CISO

 

Key Job Responsibilities

  • Advise the Senior Management and Board on Cyber and Information Security Management.
  • Formulate an institutional methodology for managing cyber and information security risks.
  • Develop the institution‟s Cyber and Information Security policy and submit it to the Senior Management and Board for approval.
  • Develop and update specific and general work procedures for realizing the institution‟s cyber and information security policy.
  • Maintain an ongoing process of cyber and information security risk assessment with the relevant institutional units, in order to analyse and assess: a) the risk levels integral to the institution's technological and business activities; b) The controls required to ensure systems integrity. c) The level of residual risk and exposure to cyber and information security threats the institution is willing to accept in implementing these activities.
  • Integrate and coordinate all institutional cyber and information security efforts, including oversight and control of all institutional units participating in these efforts.
  • Create a framework for receiving ongoing and ad-hoc reports from various institutional units.
  • Initiate and conduct cyber and information security readiness exercises as follows: a) at least quarterly, an exercise shall be staged to assess the ability of one or more institutional entities to deal with a cyber-attack; and b) once a year, an exercise shall be undertaken to assess the preparedness of the entire institution to withstand cyber-attacks.
  • Coordinate cyber and information security activities, including joint exercises with business partners and service providers.
  • Promote cyber and information security awareness and train employees, suppliers, business partners and customers.
  • Continuously learn and monitor cyber and information security issues by identifying trends, methods and advanced developments in the field while gathering information about emerging attack techniques and ways of dealing with them.
  • Form a Cyber-Incident Response Team.
  • Analyse cyber and information security incidents that have occurred in Ghana and worldwide, and assess their potential impact on the institution, as well as implement the relevant measures proposed.
  • Develop metrics and indicators to assess the effectiveness of cyber and information security systems and procedures.
  • Assess regular and ad-hoc institutional cyber and information security controls.
  • Draw up annual and multiannual work plans, including budgeting, prioritisation and timetables for implementing the assessment processes.
  • Prepare and submit annual reports to the Senior Management and Board, detailing the institutional cyber and information security defence level, weaknesses and vulnerabilities, available countermeasures, and the activities and budgets required to enhance its defences.
  • Be responsible for collaborating with relevant institutions involved in cyber and information security issues.
  • Ensure preparation of reports on major cyber and information security incidents to the Bank of Ghana.

                              

Key Performance Indicators

  • Compliance with BoG Cyber Security Requirements
  • Cyber and Information Security Audit and Risk Assessment Ratings
  • Cyber and Information Security Incidents and Events
  • Cyber and Information Security Breaches

Relationships

External                                :           Bank of Ghana, IT Vendors

Internal                                :           IT&T, Chief Executive Officer, Senior Management, Support Services

        Job Requirements

Qualification

Educational 

  • A first degree in Computer Science/ Computer Engineering/ Electrical or Telecom Engineering.

Professional                                    : Certification in Cyber and Information Security

 

Knowledge

  • Experience in Cyber and Information Security Management
  • Excellent oral and written communication skills and ability to professionally represent to Senior Management.

 

Work Experience                : Three years working experience

 

Technical Competence

  • Communication and presentation skills
  • Policy development and administration
  • Incident management
  • Knowledge of Cyber Security regulations and standards compliance
  • Risk assessment and management
  • Security architecture
  • Systems security
  • Disaster recovery