RM-9.1.12
  
  a) Cyber defense objectives, definition of areas of responsibilities, involved positions and functions (including work interfaces);
  b) Organisational structures, structure and governance of the cyber securityrisk management process at the licensee ;
  c) Internal procedural framework of the licensee , details of the controls required and the framework for their implementation;
  d) Monitoring and responses, training and awareness, information gathering, research, and sharing;
  e) Process maturity and effectiveness metrics and indexes; and
  f) Evaluation, control and reporting.
  Added: April 2019
 
  
        