Requirement:
The implementation of the cybersecurity awareness program must be reviewed periodically.
Control Implementation Guidelines:
- Review the cybersecurity requirements of cybersecurity awareness and training programs by conducting a periodic assessment (according to a documented and approved plan for review and based on a planned interval (e.g., quarterly)) to implement awareness and training plans by the Cybersecurity function and in cooperation with relevant departments (such as the Awareness and Training Department)
- Conduct application review through traditional channels (e.g., email) or automated channels using a compliance management system. The organization may develop a review plan explaining the cybersecurity requirements implementation review schedule for cybersecurity awareness and training programs
Expected Deliverables:
- Results of cybersecurity awareness program implementation review in the organization
- A document that defines the cybersecurity awareness and training implementation review cycle (Compliance Assessment Schedule)
- Compliance assessment report that shows the assessment of the implementation of cybersecurity requirements for cybersecurity awareness and training programs
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you