RJCS · Article 25

Management responsibility: deciding, supervising and proving

Cybersecurity governance is no longer just a technical matter. Management shall understand the risk, adopt measures, monitor implementation and maintain evidence of decisions.

For whom

When this article must enter into the plan.

Management, management or administration bodies of the entities concerned, in accordance with the qualification and regime specifically applicable.

Brief tutorial

Four steps to start with method.

Adapt the depth, the responsible and the evidence to the concrete framework of the entity.

  1. 01

    Define responsibilities

    Document roles, powers, scaling and relationship between management, Cybersecurity Officer (RCS), internal teams and providers.

  2. 02

    Approving the approach

    Lead to management of the risk system, priority measures, resources and acceptance criteria.

  3. 03

    Supervise execution

    establish indicators, meetings, exceptions, corrective actions and reporting of relevant incidents.

  4. 04

    Enable and register

    Plan regular management training and preserve minutes, decisions, reviews and presences.

Proof

Evidence to prepare.

  • RACI governance and matrix model
  • Minutes and deliberations
  • Risk panel and indicators
  • Management training registers

Warning

Errors that weaken implementation.

  • Delegate responsibility as if it disappeared
  • Approving policies without monitoring implementation
  • Reporting only technical activity without risk and decision

Quick control

Initial checklist.

  • Formalised papers
  • Revised risk by management
  • Measures adopted
  • Accompanyed indicators
  • Registered training

Frequently Asked Questions

Two key answers.

Appoint a Cybersecurity Officer (RCS) transfers all responsibility?

No. The Cybersecurity Officer (RCS) supports coordination, but the obligations of the management bodies themselves must be read in accordance with Article 25.

What evidence shows supervision?

Minutes, decisions, indicators, risk reviews, monitoring of actions and training records help to demonstrate effective supervision.

Primary source

Decree-Law No. 125/2025 of 4 December

Information tutorial. Always confirm the official text, the applicable regulations and the specific framework of the organization.

Consult official act

Content and references checked on .

Continue the route

Return to the full map of the Decree-Law.

See the other articles, chapters, attachments and operational tutorials.

Back to Operational Reading