‹ RM-3.1.1 RM-3.1.3 › RM-3.1.2 Licensees must ensure that the cyber security risk management framework encompasses, at a minimum, the following components: a) Cyber security strategy; b) Cyber security policy; and c) Cyber security risk management approach, tools and methodology and, an organization-wide security awareness program. Added: January 2022 ‹ RM-3.1.1 RM-3.1.3 ›