COI Report – Part VII
Page
348 of
425 attention and resources are directed and prioritised by the senior management within the organisation. c)
Relatedly,
and as we have also explained, Dr Lim also expressed the view that the senior management making decisions on risks would need to be equipped with technical expertise/competency to appreciate and manage the risks.
1006. Inline with these recommendations, it would follow that it
is for senior management to articulate the organisation’s risk appetite, and we recommend that a clear cybersecurity risk appetite statement be drawn up and regularly reviewed and updated by senior management.
Share with your friends: