The cybersecurity program addresses and enables the achievement of legal and regulatory compliance, as appropriate
Context and Guidance: The organisation should have personnel who are responsible for ensuring that it is aware of all regulatory compliance obligations that it is subject to from governments and other sources. Cybersecurity program objectives should align with and support the meeting of any of those obligations that are relevant to cybersecurity, and the program should develop and implement the proper procedures and activities to ensure compliance in a timely and accurate manner.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: PROGRAM-2b, PROGRAM-2g, PROGRAM-2h, PROGRAM-2i.