Regulated Incident Management Ecosystem Versão portuguesa

Service sheet CSO-05

Governance and Management Bodies

Definition of the cybersecurity governance model and training of the management body on its own responsibilities.

The problem it solves

The Act places responsibilities on the management body itself, including approving the measures and receiving training. Many management bodies are unaware of this and delegate what cannot be delegated.

Who it is for

  • Board members and executives;
  • Public sector leaders;
  • General secretaries and supervisory boards.

Deliverables

  • Governance model and decision chain;
  • Template minutes approving the measures;
  • Three-hour executive training session;
  • Indicator dashboard for the management body.

Method

  1. 01

    Frame

    Duties of the management body.

  2. 02

    Design

    Model and decision chain.

  3. 03

    Train

    Executive session.

  4. 04

    Monitor

    Indicators and review.

Regulatory basis

  • Article 25 of Decree-Law 125/2025, on approval of the measures and on the responsibility and training of the members of the management body;
  • Articles 61 to 65 of the same act, on the penalty framework.

Expected results

  • Duties of the management body understood;
  • Decisions documented and defensible;
  • A cybersecurity role with a real mandate.

Ecosystem links

An appointed role is not yet a role performed

Start by checking your organisation scope or ask for a proposal to structure the role.