Organizations should include:

  • Minimum cybersecurity controls (e.g., access control, encryption)
  • Incident reporting obligations
  • Audit and compliance requirements
  • Data protection and confidentiality clauses