The Chief Information Security Officer (CISO), or Information Security Officer in smaller organisations, coordinates the information security programme across the organisation. They maintain the Risk register together with Stakeholders and Risk owners, coordinate the implementation of Controls with Control owners, and report the organisation's overall risk posture to senior management.
The CISO works closely with, but is a distinct role from, the Data Protection Officer (DPO): the CISO is responsible for information security in general (confidentiality, integrity, availability of all assets), while the DPO focuses specifically on the legal obligations around personal data. In Swiss government projects the two functions are often addressed jointly under the “ISDS” (information security and data protection) umbrella.