The organisation's cybersecurity risk management performance shall be evaluated, reviewed and adapted when necessary.