Requirement:
Cybersecurity requirements for protecting and handling data and information must be defined, documented and approved as per the related laws and regulations.
Control Implementation Guidelines:
- Cybersecurity requirements for data and information protection must be included and documented in line with policies issued by the National Data Management Office, including but not limited to:
- Data and Information Protection Requirements
- Data and Information Ownership Requirements
- Data and information Classification and Labelling Requirements
- Data and Information Privacy Requirements
- The policy must be supported by the Executive Management. This must be done through the approval of the organization head or his/her deputy
Relevant Cybersecurity Tools:
- Data Security Policy Template
Expected Deliverables:
- Cybersecurity policy that covers the requirements of Data and Information Protection in the organization (e.g., electronic copy or official hard copy)
- Formal approval by the head of the organization or his/her deputy on the policy (e.g., via the organization's official e-mail, paper or electronic signature)
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you