Establish and maintain effective information security governance and provide periodic reporting to executive management and the Board or its designated committee on the Bank's risk profile, material threats and vulnerabilities, significant incidents, control effectiveness, testing results, remediation status, third-party risks, program performance, and resource needs. Develop, maintain, and oversee a documented, enterprise-wide information security risk assessment process that identifies reasonably foreseeable internal and external threats, evaluates the likelihood and potential impact of those threats, assesses the sufficiency of existing controls, prioritizes residual risks, and tracks remediation to completion.