Requirement:
The requirements for cybersecurity incidents and threat management must be reviewed periodically.
Control Implementation Guidelines:
- Review the cybersecurity requirements of cybersecurity incident and threat management by conducting a periodic assessment (according to a documented and approved plan for review, and based on a planned interval "e.g., quarterly") to implement cybersecurity incident and threat management requirements by the Cybersecurity function and in cooperation with relevant departments (such as IT Department)
- Conduct application review through traditional channels (e.g., email) or automated channels using a compliance management system. The organization may develop a review plan explaining the implementation review schedule for cybersecurity incident and threat management
- Review and update cybersecurity requirements for cybersecurity incident and threat management in the organization periodically according to a documented and approved plan for review and based on a planned interval or in the event of changes in relevant laws and regulations
- Document the review and changes to the cybersecurity requirements for cybersecurity incident and threat management in the organization and approve them by the head of the organization or his/her deputy
Expected Deliverables:
- Results of Cybersecurity Incident and Threat management requirements implementation review in the organization
- A document that defines the cybersecurity requirements implementation review cycle for cybersecurity incident and threat management within the organization (Compliance Assessment Schedule)
- Compliance assessment report that outlines the assessment of the implementation of cybersecurity requirements for cybersecurity incident and threat management
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you