The organization shall incorporate improvements derived from the monitoring, measurements, assessments, and lessons learned into protection process updates (continuous improvement).
The organization shall implement independent teams to assess the protection process(es).
The organization shall ensure that the security plan for its critical systems facilitates the review, testing, and continual improvement of the security protection processes.