One such process is risk acceptance. As part of operational risk management, it includes input and
analysis on cyber resilience and business continuity from relevant staff at all levels, including business
units, internal audit, the chief information security officer and the board.