The asset owner shall have policies and procedures around identifying, documenting, and mitigating or otherwise managing IACS cybersecurity risks, including determining a tolerable risk level and responding to risks outside that tolerable risk level.