1.1 Data Governance and Cyber Security Strategies for critical assets
- Cyber Security Strategy and Plans that include the identification and prioritisation of critical assets including data, systems, technology infrastructure and physical assets for those operating critical infrastructure such as power generation, water treatment, telecommunications, etc.
- Data Governance Strategy aligned with criticality of data, emerging threats, privacy laws and current legislation.
2.2 Cyber Security Architecture and controls effective for current and emerging risks
- Cyber Security Architecture and Controls that protect the security of critical assets and are designed for current and emerging threats.
- Monitoring, detection, identification and escalation processes to identify and respond to cyber security threats.
- Penetration testing and reporting.
2.3 Alignment of plans and stakeholder management
- Cyber response plans aligned with other response plans within the business including Incident Management Plan and Crisis Management Plan.
- Cyber response plans aligned with third party providers and external organisations where required.
- Stakeholder Management Plan that includes pre-considered strategies to manage and communicate with staff, regulators, customers, shareholders, media and the community should be understood and documented.
2.4 Cyber resilience training and awareness program
- Training and Awareness Program to develop the knowledge and skills of individuals and teams to build cyber resilience cultures and includes practitioner training, user training and all staff including executives and board members.


