3.1Programme resources and asset classification
3.2Industry standards and frameworks
3.3Security control design, selection and implementation
3.4Security awareness training and communication
3.5Third-party service management
3.6Programme metrics and reporting