The organization has a process in place to ensure that any changes to the business strategy or the digital operational resilience strategy are assessed for potential ICT risks.
The ICT risk management function, in coordination with relevant stakeholders, reviews such changes to identify new risks or impacts on existing ICT controls, systems, or processes.
Any identified risks are recorded in the ICT risk register, and appropriate risk treatment measures are considered. This process ensures that strategic decisions are aligned with the organization’s ICT risk management framework and that risks arising from strategic changes are properly assessed, documented, and governed.