Requirement:
The cybersecurity requirements for protecting information systems and information processing facilities must be reviewed periodically.
Control Implementation Guidelines:
- Review the cybersecurity requirements for Information System and Processing Facilities Protection in the organization periodically according to a documented and approved plan for review and based on a planned interval (e.g., periodic review must be conducted annually)
- Document the review and changes to the cybersecurity requirements for Information System and Processing Facilities Protection in the organization and approve them by the head of the organization or his/her deputy
Expected Deliverables:
- An approved document that defines the review schedule for the requirements document
- Evidence that the periodic review of security requirements is performed to protect information systems and processing facilities in the organization
- Formal approval by the head of the organization or his/her deputy on the updated requirements (e.g., via the organization's official e-mail, paper or electronic signature)
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you