Requirement:
The cybersecurity risk management methodology and procedures must be reviewed periodically according to planned intervals or upon changes to related laws and regulations. Changes and reviews must be approved and documented.
Control Implementation Guidelines:
- Review and update the cybersecurity risk management methodology and procedures and cybersecurity risk management requirements in the organization periodically according to a documented and approved plan for review and based on a planned interval (e.g., periodic review must be conducted annually)
- Review and update the cybersecurity risk management methodology and procedures and cybersecurity risk management requirements in the organization in the event of changes in the relevant laws and regulations (for example, when a new cybersecurity law is issued that applies to the organization)
- Document the review and changes to the cybersecurity requirements related to cybersecurity risk management methodology and procedures and approve them by the representative
Expected Deliverables:
- An approved document that defines the review schedule for the cybersecurity risk management methodology and procedures
- Cybersecurity risk methodology and procedures indicating that they have been reviewed and updated, and that changes have been documented and approved by the representative
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you