RM-9.1.11
A corporate-wide cyber security risk defense strategy must be defined and documented, which includes:
  a) The position and importance of cyber security risk defense at the licensee ;
  b) The cyber security risk-threat concept and the challenges facing the licensee ;
  c) The licensee's  approach to cyber security risk management, definition and oversight the level of exposure to cyber security risk threats; and
  d) The key elements of cyber security risk defense strategy – objectives, principles of operation and implementation.
  Added: April 2019
 
  
        