RM-9.1.12

Past version: Effective from 01 Apr 2019 to 30 Sep 2021
To view other versions open the versions tab on the right

Licensees must establish a cyber security risk policy, which includes:

a) Cyber defense objectives, definition of areas of responsibilities, involved positions and functions (including work interfaces);
b) Organisational structures, structure and governance of the cyber securityrisk management process at the licensee;
c) Internal procedural framework of the licensee, details of the controls required and the framework for their implementation;
d) Monitoring and responses, training and awareness, information gathering, research, and sharing;
e) Process maturity and effectiveness metrics and indexes; and
f) Evaluation, control and reporting.
Added: April 2019