Requirement:
The cybersecurity roles and responsibilities must be reviewed periodically according to planned intervals or upon changes to related laws and regulations.
Control Implementation Guidelines:
- Review the cybersecurity roles and responsibilities in the organization periodically according to a documented and approved plan for review and based on a planned interval (e.g., periodic review must be conducted annually)
- Review and update the cybersecurity roles and responsibilities in the organization in the event of changes in the relevant laws and regulations (for example, when a new cybersecurity law is issued that applies to the organization)
- Document the review and changes to the cybersecurity requirements related to cybersecurity roles and responsibilities and approve them by the representative
Expected Deliverables:
- An approved document that defines the review schedule for the roles and responsibilities
- Roles and responsibilities document indicating that they are up to date and the changes to the cybersecurity requirements for roles and responsibilities have been documented and approved by the representative
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you