The secretary shall, notwithstanding section 45 of chapter 30 and chapter 31, appoint a qualified individual to serve as an enterprise chief information security officer (CISO) for the commonwealth who shall serve at the pleasure of the secretary. The CISO shall advise the secretary and the CIO on preventing data loss and fraud and protecting privacy. The CISO shall ensure all existing IT policies applicable to executive offices and agencies reflect best practices related to security and privacy.
Mass. Gen. Laws ch. 7D, § 4
Enterprise chief information security officer (CISO)
Official source: Massachusetts Legislature. Reproduced from public-domain Massachusetts statutes; confirm against the official source for the current text. Not legal advice.