CTDISR-2025 Section 1 mandates an Information Security Steering Committee chaired by the CEO with board-level cybersecurity reporting. The ISSC is the governance structure that gives cybersecurity accountability at executive level rather than leaving it as an operational function with no management visibility.
For most Pakistani ISPs, this is new governance territory. An ISSC does not need to be elaborate: it needs to exist formally, meet at a defined cadence, cover the required topics, and produce minutes that an auditor can review to verify that governance is actually happening.
ISSC Composition
The minimum composition for a CTDISR-compliant ISSC: the CEO as chair (mandatory, CTDISR-2025 requires CEO chairmanship), the CISO as the operational lead who prepares and presents the security agenda, and heads of any significant operational functions (NOC lead, IT lead, finance lead for operators where financial system risk is material).
For smaller ISPs where these roles overlap (the CEO is also the operations lead, the CISO is fractional), the composition can be lean as long as the CEO is genuinely chairing and the CISO function is genuinely preparing and presenting security information. An ISSC where the CEO signs attendance sheets but is not engaged in the discussions will be visible to an experienced auditor through the minutes.
Meeting Cadence
Quarterly is the standard ISSC meeting cadence and the minimum that satisfies CTDISR-2025. For operators approaching their first audit cycle or operating through significant security events, monthly meetings during the run-up period are appropriate.
Schedule meetings at the start of the year and send calendar invitations for all four quarterly meetings immediately. Meetings that require scheduling from scratch each quarter are frequently postponed, and an ISSC with two meetings in a year instead of four is a Section 1 finding.
Agenda Structure
A standard ISSC agenda covers six topics that together constitute an adequate governance review:
Previous meeting actions: status of action items from the last meeting. Any open items with past-due dates require explanation.
Security posture summary: the CISO presents the current security posture using the traffic-light metrics format from the security metrics article. Top risks, any changes since last meeting, trend direction.
Compliance status: CTDISR-2025 compliance posture across all 19 sections, expressed as a percentage of controls implemented and evidenced, with any sections in red or amber status explained and remediation plans presented.
Incident summary: any security incidents since the last meeting, their classification, impact, response, and resolution. For the 24-hour PTA reporting obligation, any incidents that were reported to PTA are noted with the notification date.
Risk register review: any new risks added since the last meeting, any risks where treatment status has changed significantly, any risks requiring board-level decision on treatment approach.
Upcoming actions and decisions: any decisions the ISSC needs to make, upcoming audit dates, planned security investments requiring approval, and the action register for the next meeting period.
Minutes as Audit Evidence
The meeting minutes are the primary evidence that the ISSC is functioning rather than existing only on paper. Good minutes for CTDISR evidence purposes record: the date and attendees (with the CEO listed as chair), each agenda item discussed, the specific information presented under each item (not just "security update presented" but the substance of what was covered), any decisions made, and the action items with named owners and due dates.
Minutes that read as genuine records of a substantive discussion look different from minutes produced to satisfy an audit requirement. An auditor who reviews four quarters of ISSC minutes where every meeting has the same generic text and no evidence of actual deliberation will note it. Minutes that show the ISSC discussed a specific incident, made a specific decision about a remediation investment, or raised concerns about a specific control gap are credible governance evidence.
Board-Level Reporting
The CTDISR-2025 board reporting requirement is satisfied when the ISSC's output reaches the board of directors (or equivalent governance body). For operators where the ISSC itself includes all board members, the ISSC meeting is the board reporting event. For operators with a separate board and an ISSC that reports to it, a brief board security report should be produced quarterly, summarising the ISSC's security posture findings and any decisions requiring board-level approval.
The board report format should be executive-level: traffic-light summary of overall posture, headline risks, compliance status, and any items requiring board decision. Technical detail stays in the ISSC reports. The board needs enough information to exercise governance accountability, not enough to manage the security programme.
For operators using CISO-as-a-Service, ISSC setup, facilitation, and board reporting are core deliverables. For tracking ISSC meeting records and governance evidence alongside all CTDISR compliance documentation, ComplianceIQ manages the full evidence set.