The organization must define, document, and formally approve its set of cybersecurity policies and measures. This comprehensive set of measures must be appropriate for the organization's size, risk profile, and complexity, and it must be based on the findings of the official risk analysis.
When defining these measures, the organization must take into account the guidelines provided in the National Cybersecurity Reference Framework (QNRCS), the latest technical developments, and relevant international standards (e.g., ISO/IEC 27001).