GV.OC-03: How to manage legal, regulatory, and cybersecurity obligations ?
GV.OC-03: Legal, regulatory, and contractual requirements regarding cybersecurity – including privacy and civil liberties obligations – are understood and managed.
Example 1: Determine a process to track and manage legal and regulatory requirements regarding protection of individuals’ information (e.g., Health Insurance Portability and Accountability Act, California Consumer Privacy Act, General Data Protection Regulation).
Example 2: Determine a process to track and manage contractual requirements for cybersecurity management of supplier, customer, and partner information.
Example 3: Align the organization’s cybersecurity strategy with legal, regulatory, and contractual requirements.
GV.OC-05: Outcomes, capabilities, and services that the organization depends on are determined and communicated Implementation Examples Example 1: Create an inventory of the organization’s dependencies on…
GV.OC-04: Critical objectives, capabilities, and services that stakeholders depend on or expect from the organization are determined and communicated. Implementation Examples Example 1: Establish criteria…
Leave a Reply