Requirement:
The cybersecurity policies and procedures must be reviewed periodically according to planned intervals or upon changes to related laws and regulations. Changes and reviews must be approved and documented.
Control Implementation Guidelines:
- Review the cybersecurity policies, procedures, and standard controls in the organization periodically according to a documented and approved plan for review and based on a period specified in the policy (e.g., periodic review must be conducted annually)
- Review and update the cybersecurity policies, procedures, and standard controls in the organization in the event of changes in the relevant laws and regulations (for example, when a new cybersecurity law is issued that applies to the organization).
- Document the review and changes to the cybersecurity policies, procedures, and standard controls and approve them by the head of the organization or his/her deputy
Expected Deliverables:
- An approved document that defines the review schedule
- An approved document that clarifies the review of cybersecurity policies, procedures and standard controls in the organization on a periodic basis based on the period of time set for review
- Policies, procedures, and standard controls documents indicating that they have been reviewed and updated, and that changes have been documented and approved by the representative
- Official approval and approval by the representative on updated policies, procedures, and standard controls
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you