Security Officer
Regulation
The map of applicable requirements.
Regulatory map
Applicable instruments
| Instrument | Subject | Relevant provisions |
|---|---|---|
| GDPR | Personal data protection | Articles 5(2), 24, 28, 32 and 39 |
| Law 58/2019 | National implementation of the GDPR | Duties of the data protection officer and penalties |
| Decree-Law 125/2025 | Portuguese Cybersecurity Act | Applicable to covered entities; see cybersecurityofficer.pt |
| ISO/IEC 27001 and 27002 | Management system and controls | Certification framework |
| ISO 22301 | Business continuity | Impact analysis and testing |
Informative summary. Always check the official text in force.
Security that is not measured is not managed
Start with a maturity assessment or ask for a proposal to structure the role.