The organization shall conduct a regular self-assessment of its cybersecurity management system to verify its compliance with security documentation and the effective implementation of cybersecurity risk management measures. This self-assessment should be carried out at least every two years or after a significant security incident.
The self-assessment process should be documented to ensure repeatability and should include:
- Verification of compliance with internal security documentation.
- Assessment of the implementation and effectiveness of cybersecurity risk management measures.
Based on the self-assessment results:
- If the organization is found to be compliant, a declaration of compliance shall be prepared, detailing the elements that enable the repeatability of the assessment.
- If non-compliances are identified, a declaration of non-compliance shall be prepared. This declaration must clearly state the identified non-compliances, the proposed methods for their remediation, and the deadlines for their implementation.
The self-assessment can be conducted as part of the organization's internal audit program.