PROGRAM-1e — Program Structure and Organization
Section 6.10, Cybersecurity Program Management (PROGRAM), Objective 1
Relevant requirement: The cybersecurity program strategy defines the structure and organization of the cybersecurity program.
Reference details and direct document links for documenting OT/ICS cybersecurity roles, responsibilities, authorities, and accountability across operations, supply chain, vendors, and key onshore/offshore personnel.
Ensure OT/ICS roles offshore are defined and documented. Roles should cover operations, supply chain, vendors, support personnel, and other key stakeholders involved in OT/ICS cybersecurity execution or decision-making.
Section 6.10, Cybersecurity Program Management (PROGRAM), Objective 1
Relevant requirement: The cybersecurity program strategy defines the structure and organization of the cybersecurity program.
Appendix A, CSF Core, GOVERN Function
Relevant requirement: Cybersecurity roles, responsibilities, and authorities are established and communicated to foster accountability, performance assessment, and continuous improvement.
Program Management control family
Relevant requirement: The program plan includes identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
Section 3.3, Development and Deployment of an OT Cybersecurity Program
Relevant requirement: OT cybersecurity roles and responsibilities should be coordinated and aligned with internal roles and external partners.