For the duration of the Service Engagement the security and data protection policy defined must be evaluated for
business and technology environment and if possible adjusted so the policy stays aligned with the Capgemini standards
and the specific client requirements.
Having changed the policy, any related security and data protection controls and measures need to be updated as well.
Vulnerability and Threat assessments, audits, management reviews and security and data protection breaches can also
provide inputs to update controls and measures. If impact of the changes is significant for the Service Engagement, an
update of the Security And Data Protection Management Plan must be carried out.
|