As part of the company's overall risk management, a comprehensive strategy to manage information security and cybersecurity risks shall be developed and updated when changes occur.
Information security and cybersecurity risks shall be documented, formally approved, and updated when changes occur.