What gov.uk says. The Senior Responsible Officer is accountable for cyber security risk on the digital service. A Security Working Group oversees and co-ordinates day-to-day activity, with all decisions counter-signed by the SRO. An independent security consultant should sit within the SyWG so the team is not assessing its own work. The risk appetite is agreed in writing and reviewed when expected risk changes.
What Secruna captures via the checklist. The SRO appointment in writing (with the supporting letter or PID minute attached), the agreed risk appetite signed off by the SRO, the SyWG terms of reference and meeting cadence, the independent security consultant’s membership, the RACI matrix mapping roles to each Secure by Design activity, and the consultation record with the information owners for the data the service processes. Each item carries an evidence-examples block listing the artefacts gov.uk recommends, so the delivery team collects a signed letter, not a free-text claim.
See this in your dashboard at: /checklists/secure-by-design#create_responsibility_for_cyber_security_risk with per-item answers, evidence attachments and the SRO sign-off cadence surfaced.