RJCS · Article 25
Management responsibility: deciding, supervising and proving
Cybersecurity governance is no longer just a technical matter. Management shall understand the risk, adopt measures, monitor implementation and maintain evidence of decisions.
For whom
When this article must enter into the plan.
Management, management or administration bodies of the entities concerned, in accordance with the qualification and regime specifically applicable.
Brief tutorial
Four steps to start with method.
Adapt the depth, the responsible and the evidence to the concrete framework of the entity.
- 01
Define responsibilities
Document roles, powers, scaling and relationship between management, Cybersecurity Officer (RCS), internal teams and providers.
- 02
Approving the approach
Lead to management of the risk system, priority measures, resources and acceptance criteria.
- 03
Supervise execution
establish indicators, meetings, exceptions, corrective actions and reporting of relevant incidents.
- 04
Enable and register
Plan regular management training and preserve minutes, decisions, reviews and presences.
Proof
Evidence to prepare.
- RACI governance and matrix model
- Minutes and deliberations
- Risk panel and indicators
- Management training registers
Warning
Errors that weaken implementation.
- Delegate responsibility as if it disappeared
- Approving policies without monitoring implementation
- Reporting only technical activity without risk and decision
Quick control
Initial checklist.
- Formalised papers
- Revised risk by management
- Measures adopted
- Accompanyed indicators
- Registered training
Frequently Asked Questions
Two key answers.
Appoint a Cybersecurity Officer (RCS) transfers all responsibility?
No. The Cybersecurity Officer (RCS) supports coordination, but the obligations of the management bodies themselves must be read in accordance with Article 25.
What evidence shows supervision?
Minutes, decisions, indicators, risk reviews, monitoring of actions and training records help to demonstrate effective supervision.
Primary source
Decree-Law No. 125/2025 of 4 December
Information tutorial. Always confirm the official text, the applicable regulations and the specific framework of the organization.