Maintain a risk-based security program
Identify assets and nonpublic information, document risk, assign accountable security leadership and obtain the required policy approval. Map each applicable Part 500 provision and exemption to an owner.
Annual
At material risk changes and the company’s annual program review
Identify assets and nonpublic information, document risk, assign accountable security leadership and obtain the required policy approval. Map each applicable Part 500 provision and exemption to an owner.
- Risk assessment, policy approval and scope register
Controlled record with date, owner, source and review history
CISO
Leela can prepare the artifact and hand it to a person for review.
Leela can prepare a draft and evidence checklist for the accountable reviewer. Adoption and legal conclusions require human review.
Tell Leela about your company to see whether this applies.
Tell Leela how you handle it today, or hand it over: see what’s next.