graphgrc

SCF - PRM-02 - Cybersecurity & Data Privacy Resource Management

Mechanisms exist to address all capital planning and investment requests, including the resources needed to implement the cybersecurity & data privacy programs and document all exceptions to this requirement.

Mapped framework controls

ISO 27001

ISO 27002

SOC 2

Control questions

Does the organization address all capital planning and investment requests, including the resources needed to implement the cybersecurity & data privacy programs and document all exceptions to this requirement?