The asset owner shall have policies and procedures related to data integrity protection from compromise, whether at rest or in motion (electronically or physically), that takes into account applicable risks.