The cyber risk management program is established and maintained to perform cyber risk management activities according to the cyber risk management strategy
The cybers risk management program is typically responsible for ensuring that the cyber risk management objectives as documented in the cyber risk management program strategy are achieved. For example, the cyber risk management program includes activities to ensure that the organization identifies, analyzes, and responds to cyber risks.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-1a, RISK-1b, RISK-1c, RISK-1g, RISK-1h.