2603.0—2603.0
>Control Description
The Supplier shall ensure that managers, systems administrators, and users of organisational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organisational information systems. The Supplier shall review and update these security risks at least every 12 months or when there is significant change within the organisation or threat.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.