Protective Security Policy Framework (PSPF) Release 2026
Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0020: 0020 Consider the security plan annually and review it at least every two years

Requirement 0020 (Part One: Governance, section 3.1.2 Security Planning, Incidents and Training; applies to All entities; dated 31 October 2024; retained from Release 2025): The security plan is considered annually and reviewed at least every two years to confirm its adequacy and ability to adapt to shifts in the entity's risk, threat or operating environment. Annual consideration decides whether updates are needed; a formal review at least every two years confirms adequacy and adaptation to changes in risk, threat level or business impact level.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part One: Governance (sections 1 to 4) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.