CYBERSECURITY RISK MANAGEMENT PROGRAM OBJECTIVES (CYBERSECURITY OBJECTIVES)

DC4: The process for establishing, maintaining, and approving cybersecurity objectives to support the achievement of the entity's objectives
  • The process for establishing cybersecurity objectives based on the entity's business and strategic objectives established by the board of directors and management
  • The process for obtaining board of director or executive management approval of the entity's cybersecurity objectives
  • The use of security management and control frameworks in establishing the entity's cybersecurity objectives and developing and maintaining controls within the entity's cybersecurity risk management program, including disclosure of the particular framework(s) used (for example, NIST Cybersecurity Framework, ISO 27001/2 and related frameworks, or internally- developed frameworks based on a combination of sources)

FACTORS THAT HAVE A SIGNIFICANT EFFECT ON INHERENT CYBERSECURITY RISKS

DC5: Factors that have a significant effect on the entity's inherent cybersecurity risks, including the (1) characteristics of technologies, connection types, use of service providers, and delivery channels used by the entity, (2) organizational and user characteristics, and (3) environmental, technological, organizational and other changes during the period covered by the description at the entity and in its environment.
  • Changes to the entity's principal products, services, or distribution methods
  • Significant changes to entity processes, IT architecture and applications, and the processes and systems used by outsourced service providers
  • Acquisitions and other business units that have not been fully integrated into the cybersecurity risk management program including the integration or segmentation strategy used for the acquiree's IT systems, and the current state of those activities
  • Changes to legal and regulatory requirements
  • Divestures and other cessation of operations, particularly those that have ongoing service support obligations for systems related to those operations (if any), and the current status of those activities
DC6: For security incidents that (1) were identified during the 12-month period preceding the period end date of management's description and (2) resulted in a significant impairment of the entity's achievement of its cybersecurity objectives, disclosure of the following (a) nature of the incident; (b) timing surrounding the incident; and (c) extent (or effect) of those incidents and their disposition
  • Was considered sufficiently significant based on law or regulation to require public disclosure
  • Had a material effect on the financial position or results of operations and required disclosure in financial statement filings
  • Resulted in sanctions by any legal or regulatory agency
  • Resulted in withdrawal from material markets or cancellation of material contracts
Main Menu