+DORA Ch. II Sec. I Art. 5 2.

DORA Ch. II Sec. I Art. 5 2.

2.   The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework referred to in Article 6(1).

For the purposes of the first subparagraph, the management body shall:

  • (a) bear the ultimate responsibility for managing the financial entity’s ICT risk;
  • (b) put in place policies that aim to ensure the maintenance of high standards of availability, authenticity, integrity and confidentiality, of data;
  • (c) set clear roles and responsibilities for all ICT-related functions and establish appropriate governance arrangements to ensure effective and timely communication, cooperation and coordination among those functions;
  • (d) bear the overall responsibility for setting and approving the digital operational resilience strategy as referred to in Article 6(8), including the determination of the appropriate risk tolerance level of ICT risk of the financial entity, as referred to in Article 6(8), point (b);
  • (e) approve, oversee and periodically review the implementation of the financial entity’s ICT business continuity policy and ICT response and recovery plans, referred to, respectively, in Article 11(1) and (3), which may be adopted as a dedicated specific policy forming an integral part of the financial entity’s overall business continuity policy and response and recovery plan;
  • (f) approve and periodically review the financial entity’s ICT internal audit plans, ICT audits and material modifications to them;
  • (g) allocate and periodically review the appropriate budget to fulfil the financial entity’s digital operational resilience needs in respect of all types of resources, including relevant ICT security awareness programmes and digital operational resilience training referred to in Article 13(6), and ICT skills for all staff;
  • (h) approve and periodically review the financial entity’s policy on arrangements regarding the use of ICT services provided by ICT third-party service providers;
  • (i) put in place, at corporate level, reporting channels enabling it to be duly informed of the following:
    • (i) arrangements concluded with ICT third-party service providers on the use of ICT services,
    • (ii) any relevant planned material changes regarding the ICT third-party service providers,
    • (iii) the potential impact of such changes on the critical or important functions subject to those arrangements, including a risk analysis summary to assess the impact of those changes, and at least major ICT-related incidents and their impact, as well as response, recovery and corrective measures.

1. Overview

Summary Regulation

1.1 References

1.2 Identified Requirements

1.3 Related Standards

2. Identified Requirements

Requirements
Source Requirement

3. Related Standards

Standards
Source Requirement
NOREA Resilience Training Programs
Implement security awareness and digital operational resilience training as integral components of staff training schemes and ensure training extends to all staff members, including senior management. Customize training intensity based on employee roles and functions. For the training content, cover topics such as network security, insights from prior incidents, threat intelligence, defenses against intrusions, data protection measures (e.g., encryption, cryptography). Conduct the resilience training program on an annual basis. Staff shall be informed on the ICT security policies, procedures and protocols and be made aware of the reporting channels put in place for detecting anomalous activities. Upon termination of employment, all staff are required to return all ICT assets and information assets.
NOREA Inclusion of Third-Party Providers

Incorporate ICT third-party service providers as participants in relevant training programs, where appropriate. Third-parties shall be informed on the ICT security policies, procedures and protocols and be made aware of the reporting channels put in place for detecting anomalous activities. Upon termination of employment or contract termination, the third-parties are required to return all ICT assets and information assets that belong to the financial entity. 

NOREA Governance of ICT risk

The Management body shall take ultimate responsibility for effectively managing all ICT risks of the financial entity. As such, the management body periodically (e.g. annually) ensures:

  • Establish policies related to the availability, authenticity, integrity, and confidentiality of data, including the policy on arrangements with ICT third-party service providers (see control 2.1).
  • Define the roles, responsibilities and goverance arrangements for ICT related functions risk management (including those related to ICT third-party arrangements), including the continuous monitoring thereof.
  • Review the policy on arrangements with ICT third-party service providers and stay informed about third-party  arrangements, services provided, planned material changes regarding third- party service providers, and understand the impact of these changes on critical and important functions of the entity (including risk assessment results). 
NOREA Knowledge of the Management Body
The Management body shall ensure that it is kept up to date with sufficient knowledge and skills to understand and assess ICT risks and operations (e.g. through periodic trainings).
NOREA Digital Operational Resilience Strategy

The Management body shall set and approve the digital operational resilience strategy and periodically update when needed.

The digital operational resilience strategy  must:

  • Set out how the risk management framework will be implemented.
  • Elaborate on the alignment between the risk management framework and the business strategy and objectives.
  • Establish the ICT risk tolerance level (based on risk appetite) and the impact tolerance level for ICT disruptions.
  • Include clear security objectives, including Key Performance Indicators (KPIs) and risk metrics.
  • Elaborate on the ICT reference architecture and any changes needed to reach specific business objectives.
  • Outline the mechanisms in place to detect ICT-related incidents
  • Contain evidence to prove the current digital operational resilience situation (e.g. based on the number of major ICT-related incidents and the effectiveness of preventive measures.
  • Contain how the digital operational resilience testing is implemented (see controls under 19 and 20).
  • Outline the communication strategy in case of incidents (see 11.3)

The Management body shall allocate and review the budget required for resources to fulfill the digital operational resilience needs of the entity.

Ensure monitoring is arranged on the the effectiveness of the implementation of the digital operational resilience.

NOREA Business Continuity Oversight
The Management body reviews and approves periodically (e.g. annually) the ICT business continuity policy and the ICT response and recovery plans.
NOREA Audit Plan Approval and Review
The Management body reviews and approves periodically (e.g. annually) internal ICT audit plans, ICT audits, and material modifications to the audits.
SCF Steering Committee & Program Oversight

Description

Mechanisms exist to align security, compliance and resilience capabilities with business requirements through a steering committee or advisory board, comprised of key cybersecurity, data protection and business executives, which meets formally and on a regular basis.

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Third-party advisors (subject matter experts)
∙ Virtual CISO (vCISO) service
∙ Fractional security advisor

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Third-party advisors (subject matter experts)
∙ Virtual CISO (vCISO) service
∙ Informal security advisory committee

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Steering committee / advisory board
∙ Quarterly security committee meetings with documented minutes
∙ Cross-functional representation (IT, Legal, HR, Operations)

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Formal steering committee / advisory board
∙ Documented charter with defined roles and meeting cadence
∙ Board-level cybersecurity reporting

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Formal steering committee / advisory board
∙ Board-level Cybersecurity Committee or subcommittee
∙ Chief Information Security Officer (CISO) with board-level access
∙ Independent security advisor / external audit committee

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

SCR-CMM Level 1 criteria definitions are not available for this control:
▪ A reasonable person would conclude this control requires a structured process.
▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality.

Level 2 Planned Tracked

Cybersecurity & Data Protection Governance (GOV) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with GOV domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Governance-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ No formal Governance, Risk & Compliance (GRC) team exists. GRC roles are assigned to existing IT and/or cybersecurity personnel.
▪ Organizational leadership maintains an informal process to review and respond to trends.

Level 3 Well Defined

Cybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners.
▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform).
▪ An implemented and operational capability exists to align security, compliance and resilience capabilities with business requirements through a steering committee or advisory board, comprised of key cybersecurity, data protection and business executives, which meets formally and on a regular basis.

Level 4 Quantitatively Controlled

Cybersecurity & Data Protection Governance (GOV) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational.
▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs).
▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs).
▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties.
▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review).
▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes.
▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
SCF Status Reporting To Governing Body

Description

Mechanisms exist to provide governance oversight reporting and recommendations to those entrusted to make executive decisions about matters considered material to the organization's Security, Compliance & Resilience Program (SCRP).

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Quarterly Business Review (QBR)
∙ Simple security status dashboard (spreadsheet or slide deck)
∙ Email status updates to owner/manager

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Quarterly Business Review (QBR)
∙ Structured security metrics report (incidents, patching status, training completion)
∙ Documented reporting cadence

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Quarterly Business Review (QBR)
∙ Formal security status reports to leadership
∙ KPI/KRI dashboard (e.g., Power BI, Tableau, or GRC tool reporting)

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Quarterly Business Review (QBR)
∙ Executive security dashboard with KPIs/KRIs
∙ Board-level reporting on material risk indicators
∙ Automated reporting via GRC platform

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Quarterly Business Review (QBR)
∙ Board and audit committee cybersecurity briefings
∙ Integrated GRC dashboard with real-time metrics
∙ SEC cybersecurity disclosure-ready reporting processes (if applicable)

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

SCR-CMM Level 1 criteria definitions are not available for this control:
▪ A reasonable person would conclude this control requires a structured process.
▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality.

Level 2 Planned Tracked

Cybersecurity & Data Protection Governance (GOV) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with GOV domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Governance-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ No formal Governance, Risk & Compliance (GRC) team exists. GRC roles are assigned to existing IT and/or cybersecurity personnel.
▪ Organizational leadership maintains an informal process to review and respond to trends.

Level 3 Well Defined

Cybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners.
▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform).
▪ An implemented and operational capability exists to provide governance oversight reporting and recommendations to those entrusted to make executive decisions about matters considered material to the organization's Security, Compliance & Resilience Program (SCRP).

Level 4 Quantitatively Controlled

Utilize SCR-CMM Level 3 criteria definitions:
▪ There are no defined Level 4 criteria, since it is reasonable to assume a quantitatively-controlled process is not necessary to operationalize this control.
▪ While it may be possible to develop “metrics-driven” capabilities for this control, the criteria would be organization-specific to define.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
SCF Assigned Security, Compliance & Resilience Responsibilities

Description

Mechanisms exist to assign one or more qualified individuals with the mission and resources to centrally-manage, coordinate, develop, implement and maintain an enterprise-wide Security, Compliance & Resilience Program (SCRP).

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ Third-party advisors (e.g., virtual CISO (vCISO), Managed Security Services Provider (MSSP))
∙ Designated internal security point of contact
∙ vCISO services (e.g., Truvantis, private vCISO firms)

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ Third-party advisors (e.g., virtual CISO (vCISO), Managed Security Services Provider (MSSP))
∙ Part-time or shared security manager
∙ vCISO services with defined scope and deliverables

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ Dedicated Information Security Manager (ISM) or fractional CISO
∙ Chief Information Security Officer (CISO) or equivalent role
∙ Defined Information Security Management System (ISMS) ownership

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ Chief Information Security Officer (CISO) with defined authority and budget
∙ Security leadership team (CISO, DPO, IAM lead, etc.)
∙ Security organizational structure with clear reporting lines

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ Chief Information Security Officer (CISO) with C-suite authority and board access
∙ Security leadership organization (CISO, Deputy CISO, DPO, domain leads)
∙ Security Center of Excellence (CoE)
∙ Defined succession planning for key security roles

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

SCR-CMM Level 1 criteria definitions are not available for this control:
▪ A reasonable person would conclude this control requires a structured process.
▪ At this level of maturity, the "ad hoc" nature of performing a capability informally would indicate the intent of the control is not met due to a lack of consistency and formality.

Level 2 Planned Tracked

Cybersecurity & Data Protection Governance (GOV) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with GOV domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Governance-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ No formal Governance, Risk & Compliance (GRC) team exists. GRC roles are assigned to existing IT and/or cybersecurity personnel.
▪ A qualified individual is assigned the role and responsibilities to centrally manage, coordinate, develop, implement and maintain a cybersecurity and data protection program (e.g., cybersecurity director or Chief Information Security Officer (CISO)).
▪ The individual assigned the role and responsibilities to centrally manage, coordinate, develop, implement and maintain a cybersecurity and data protection program develops plans to implement the organization's security, compliance and resiliency-related objectives.

Level 3 Well Defined

Cybersecurity & Data Protection Governance (GOV) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with GOV domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with GOV domain capabilities are well-documented and kept current by process owners.
▪ The entity's GRC team, or similar function, is appropriately staffed and supported to implement and maintain GOV domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ Technology is leveraged to enhance the efficiency and accuracy of governance, risk management and compliance operations (e.g., GRC platform).
▪ A qualified individual is assigned the role and responsibilities to centrally-manage, coordinate, develop, implement and maintain an enterprise-wide Security, Compliance & Resilience Program (SCRP) (e.g., cybersecurity director or Chief Information Security Officer (CISO)).

Level 4 Quantitatively Controlled

Utilize SCR-CMM Level 3 criteria definitions:
▪ There are no defined Level 4 criteria, since it is reasonable to assume a quantitatively-controlled process is not necessary to operationalize this control.
▪ While it may be possible to develop “metrics-driven” capabilities for this control, the criteria would be organization-specific to define.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
SCF Defined Roles & Responsibilities

Description

Mechanisms exist to define cybersecurity roles & responsibilities for all personnel.

Possible Solutions & Considerations

Micro-Small Business (<10 staff) / BLS Firm Size Classes 1-2

∙ NIST NICE cybersecurity workforce framework alignment
∙ Responsible, Accountable, Supporting, Consulted and Informed (RASCI) matrix

Small Business (10-49 staff) / BLS Firm Size Classes 3-4

∙ NIST NICE cybersecurity workforce framework alignment
∙ Responsible, Accountable, Supporting, Consulted and Informed (RASCI) matrix

Medium Business (50-249 staff) / BLS Firm Size Classes 5-6

∙ NIST NICE cybersecurity workforce framework alignment
∙ Responsible, Accountable, Supporting, Consulted and Informed (RASCI) matrix

Large Business (250-999 staff) / BLS Firm Size Classes 7-8

∙ NIST NICE cybersecurity workforce framework alignment
∙ Responsible, Accountable, Supporting, Consulted and Informed (RASCI) matrix

Enterprise (> 1,000 staff) / BLS Firm Size Class 9

∙ NIST NICE cybersecurity workforce framework alignment
∙ Responsible, Accountable, Supporting, Consulted and Informed (RASCI) matrix

SCR-CMM

Level 0 Not Performed

Practices are non-existent, based on the inability to demonstrate an implemented and operational capability. A reasonable person would conclude the control is not being performed.

Level 1 Performed Informally

Human Resources Security (HRS) domain capabilities are ad hoc and inconsistent. Capability criteria associated with this control may include:
▪ Policies, standards & procedures associated with HRS domain capabilities provide limited coverage due to the depth and breadth of the existing documentation.
▪ Personnel management-related activities are decentralized (e.g., a localized/regionalized function) and uses non-standardized methods to implement secure, resilient and compliant practices.
▪ The Human Resources (HR) department provides guidance on secure HR practices for hiring, retaining and terminating employees, contractors and other personnel that work on behalf of the organization.
▪ Formal roles and responsibilities for cybersecurity and/or data protection are not consistent and/or standardized.

Level 2 Planned Tracked

Human Resources Security (HRS) capabilities are requirements-driven, but are not standardized across the entity (e.g., local/regional level consistency). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with HRS domain capabilities are formally documented and centrally-managed by the entity.
▪ Standardized Operating Procedures (SOP) associated with HRS domain capabilities are documented and maintained by process owners.
▪ IT and/or cybersecurity personnel work with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with HRS domain capabilities to address applicable statutory, regulatory and/or contractual requirements for Technology Assets, Applications, Services and/or Data (TAASD).
▪ Personnel management-related controls are primarily administrative and preventative in nature (e.g., policies, standards, procedures & guidelines).
▪ Personnel management is decentralized at a localized/regionalized function, where there are non-standardized methods to govern personnel matters across the organization.
▪ Localized HR practices are implemented for hiring, managing, training, investigating and terminating employees, contractors and other personnel that work on behalf of the organization.

Level 3 Well Defined

Human Resources Security (HRS) capabilities are standardized across the entity for applicability to People, Processes, Technologies, Data and/or Facilities (PPTDF) to ensure consistency for Technology Assets, Applications, Services and/or Data (TAASD). Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Policies and standards associated with HRS domain capabilities are formally documented and centrally-managed by the entity's Governance, Risk & Compliance (GRC) team, or similar function.
▪ Standardized Operating Procedures (SOP) associated with HRS domain capabilities are well-documented and kept current by process owners.
▪ A Human Resources (HR) team, or similar function, is appropriately staffed and supported to implement and maintain HRS domain capabilities.
▪ Technology is leveraged to enhance the efficiency and accuracy of human resources security operations (e.g., personnel management software solution, etc.).
▪ The entity's Governance, Risk & Compliance (GRC) team, or similar function, works with business stakeholders and process owners to appropriately scope and reasonably implement cybersecurity and data protection controls associated with HRS domain capabilities to address Minimum Compliance Requirements (MCR) (e.g., applicable statutory, regulatory and/or contractual requirements) and Discretionary Security Requirements (DSR) (e.g., entity-required controls).
▪ An implemented and operational capability exists to define cybersecurity roles & responsibilities for all personnel.

Level 4 Quantitatively Controlled

Human Resources Security (HRS) capabilities, in addition to being standardized across the entity and centrally managed to ensure consistency across Technology Assets, Applications, Services and/or Data (TAASD), efforts are metrics driven to provide sufficient insight for decision makers to predict optimal performance, ensure continued operations and/or identify areas for improvement. Capability criteria associated with this control reasonably expect the following criteria to exist:
▪ Applicable SCR-CMM Level 3 (Well Defined) capabilities are implemented and operational.
▪ Metrics reporting includes quantitative analysis of Key Performance Indicators (KPIs).
▪ Metrics reporting includes quantitative analysis of Key Risk Indicators (KRIs).
▪ Scope of metrics, KPIs and KRIs covers organization-wide cybersecurity and data protection controls, including functions performed by third-parties.
▪ Organizational leadership maintains a formal process to objectively review and respond to metrics, KPIs and KRIs (e.g., monthly or quarterly review).
▪ Based on metrics analysis, process improvement recommendations are submitted for review and are handled in accordance with change control processes.
▪ Business and technical stakeholders are involved in reviewing and approving proposed changes to evolve capabilities.

Level 5 Continuously Improving

Utilize SCR-CMM Level 3 or Level 4 (if available) criteria definitions:
▪ There are no defined Level 5 criteria, since it is reasonable to assume a continuously-improving process is not necessary to operationalize this control.
▪ Level 5 capabilities should be considered “world-class” where the control builds on Level 4 capabilities, but are continuously improving through Artificial Intelligence (AI) and/or Machine Learning (ML) technologies.
▪ While it may be possible to develop responsive capabilities for this control through the use of AI and/or ML technologies, the criteria would be organization-specific to define.
Impressum German English