Organizational cybersecurity management
Like any good cybersecurity engineering process, ISO21434 starts with organizational-level expectations. Because the cybersecurity engineering approach is about managing risk, and because different organizations have different risk appetites, discussions about cybersecurity must start at the management level of any organization. This is captured through the cybersecurity policy, which sets the stage for managing the cybersecurity risk by defining processes and responsibilities and allocating resources. Typically, organizations are used to the security policy, which governs information security management systems (ISMSs). This policy can be leveraged to expand existing policies to govern operational technology (OT) through the CSMS:
Figure 5.2 – Relationship between the Cybersecurity Policy and Cybersecurity Management System Process Handbook
Briefly, the policy is the basis for requiring a cybersecurity management...