A cyber risk management process that identifies key internal and external stakeholders andfacilitates addressing risk-related issues and information shall be created, documented, reviewed, approved, and updated when changes occur.
Guidance
External stakeholders include customers, investors and shareholders, suppliers, government agencies and the wider community.
The organization shall establish a description of the procedures for risk management processes and it has to be approved. The organization must agree about it with the organization's stakeholders.