Requirement:
Cybersecurity requirements for managing information and technology assets must be defined, documented and approved.
Control Implementation Guidelines:
- Develop and document cybersecurity requirements for information and technology assets management in the organization, including the following
- The cybersecurity requirements for types and description of information and technology asset management must be identified
- Information and technology asset classification levels requirements in terms of data included and processed, and the criticality of the technology asset from a cybersecurity perspective must be defined
- Requirements for the defined stages of the information and technology assets life cycle (including but not limited to: preservation, processing, storage, destruction, etc.) must be defined
- Roles and responsibilities requirements for the ownership and management of information and technology assets must be defined
- Support the organization's developed requirements by the Executive Management. This must be done through the approval of the representative
Relevant Cybersecurity Tools:
- Asset Management Policy Template
Expected Deliverables:
- Information asset management cybersecurity requirements (in form of policy or standard) approved by the organization (e.g., electronic copy or official hard copy)
- Formal approval by the head of the organization or his/her deputy on the requirements (e.g., via the organization's official e-mail, paper or electronic signature)
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you