1.3.1 | Alignment of the security function to business strategy, goals, mission, and objectives |
---|---|
1.3.2 | Organizational processes (e.g., acquisitions, divestitures, governance committees) |
1.3.3 | Organizational roles and responsibilities |
1.3.4 | Security control frameworks (e.g., ISO, NIST, COBIT, SABSA, PCI, FedRAMP) |
1.3.5 | Due care/due diligence |