This group should ensure that a cyber and information security strategy and assurance programme are in place and are the responsibility of someone in the business who is at board level or equivalent.
The framework should cover
It is vital that the framework and strategy are reviewed and, where necessary, updated either periodically (at intervals to be determined in the framework) or as needs arise. This is to allow for changes in business model, company growth, working practices, mergers and acquisitions, technology updates / upgrades, globalisation and, of course, the evolving threat landscape.
We value your opinion - help us improve our service by filling out a quick survey.
No thanks