Governance bodies

Four bodies are enough. More dilutes responsibility; fewer pushes technical decisions up to the executive committee.

The CRA committee

Frequency: quarterly, plus an extraordinary session on event.

Composition: executive sponsor (chair), legal department, CISO, product management, head of PSIRT, procurement as needed.

Standard agenda:

  1. Progress against the back-planning and gaps.
  2. Metrics: coverage, intervals, exposure.
  3. Compliance risk register: new rows, accepted risks.
  4. Classification register: new products, reclassifications.
  5. Support period register: commitments becoming strained.
  6. Regulatory watch: what has changed, what it implies.
  7. Decisions to arbitrate.
  8. Lessons learned from the quarter’s incidents and exercises.

Decisions at its level: portfolio prioritisation, engaging a notified body, tooling budget, accepting a residual risk, arbitration between teams.

The PSIRT cell

Frequency: standing, activated on event.

Standby composition: head of PSIRT, technical on-call, legal on-call. Active composition: incident commander, analyst, legal lead, communications, product engineering, leadership where there is commercial impact.

Activation procedure: defined in 24-hour procedure. The trigger is the qualification of active exploitation or of a severe incident.

Means to guarantee: live named access to the reporting platform, templates, user notification channel, a tested call list, a room and conferencing facilities.

The pre-market review

Frequency: at every placing on the market, and at every substantial modification.

Composition: legal department (chair), CISO, product management, project lead.

Support: the legal checklist and the technical checklist.

Output: a signed record authorising the CE marking to be affixed, or a reasoned refusal with deadlines.

This is the most important body in the arrangement, because it is the only one that blocks.

The licence policy review

Frequency: quarterly.

Composition: legal department (chair), CISO, a representative of the development teams.

Agenda: exceptions reaching expiry, new requests, changes to the lists, upstream licence changes observed, state of the register.

Output: an updated, versioned policy and an up-to-date exception register.

Reporting to the executive committee

Frequency: twice yearly, or on event.

Format: one page. Three coverage metrics, three risk metrics, the state of the back-planning, the decisions required.

What must not appear: technical detail, and the number of vulnerabilities detected — a figure that rises as the arrangement improves, and is therefore uninterpretable out of context.

The principle that binds them

Every body produces written minutes with named decisions. A decision with no name is not a decision; a meeting with no minutes did not happen, from an inspection’s point of view.