GDPR questions and answers

GDPR: QUESTIONS AND ANSWERS

Category:
IT Security

Should the Management Board representative for NIS2 implementation and maintenance be a member of the IT department?

ANSWER

The Management Board representative for NIS2 implementation and maintenance does not necessarily need to be a member of the IT department. Whilst IT professionals possess specialist technical knowledge, the representative should above all have project management skills, an understanding of business processes, and awareness of the legal regulations governing cybersecurity.

The optimal solution is to appoint a person with a broad perspective, who may come from the IT department but also has experience in risk and project management as well as legal knowledge relating to NIS2. Alternatively, a dedicated team may be established in which an IT professional works alongside a person responsible for oversight and regulatory compliance.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.
Can an IT employee be the Management Board representative for NIS2 compliance? | ODO 24 | ODO 24