CYBERSECURITY RISK GOVERNANCE STRUCTURE

DC7: The process for establishing, maintaining, and communicating integrity and ethical values to support the functioning of the cybersecurity risk management program
  • How management sets the tone at the top
  • The establishment and enforcement of standards of conduct for entity personnel
  • The process used to identify and remedy deviations from established standards
  • Consideration of contractors and vendors in process for establishing standards of conduct, evaluating adherence to those standards, and addressing deviations in a timely manner
DC8: The process for board oversight of the entity's cybersecurity risk management program
  • The extent of the board of directors' cybersecurity and IT expertise or access to external cybersecurity and IT expertise, or both
  • Identification of the board committee designated with oversight of the entity's cybersecurity risk management program, if any
  • The frequency and detail with which the board or committee reviews or provides input into cybersecurity-related matters, including board oversight of security incidents
DC9: Established cybersecurity accountability and reporting lines
  • The responsibility for the review and oversight of the cybersecurity risk management program by senior management
  • The identification of the designated cybersecurity leader (for example, chief information security officer), and the reporting of that individual to executive management and board of directors
  • The roles and responsibilities of entity personnel who perform cybersecurity controls and activities
  • The process for addressing the oversight and management of external parties (for example, vendors) when establishing structures, reporting lines, authorities, and responsibilities
DC10: The process used to hire and develop competent individuals and contractors and to hold those individuals accountable for their cybersecurity responsibilities
  • The process for considering the competence of qualified personnel with cybersecurity responsibilities, including the performance of background checks, assessment of educational levels and certifications, requirements for ongoing training, hiring contractors, and the use of offshore recruiting
  • The program for providing cybersecurity awareness and training to employees and contractors based on their cybersecurity responsibilities and access to information and information systems
  • The process for making sure that employees and contractors have the resources necessary to carry out their cybersecurity responsibilities
  • The process for identifying the types and levels of cybersecurity professionals needed
  • The processes used to communicate performance expectations and hold individuals accountable for the performance of their responsibilities
  • The processes to update communication and accountability mechanisms and monitor employee compliance with their responsibilities and entity policies
  • The process used to reward individuals for performance and the process used to align the measures used to the achievement of the entity's objectives
Main Menu