Should there be a SOP on Cybersecurity?

Hi everyone,

Cybersecurity risk management has become increasingly important. Should companies now have an SOP to document how to handle cybersecurity risk management, if the company makes networked devices or software as medical devices? Thanks!
