While, generally speaking, it's a good practice to harmonize this, there are some considerations when legislating that requirement. As it relates to cybersecurity, there are different international standards bodies, and thus different organizations can follow different standards. Legislating a certain type runs the risk of requiring a certain group to adhere to those particular standards.
The other issue is that standards change consistently, so embedding those in legislation runs the risk of that provision stale-dating quickly should there be a significant enough change.
I don't know if my colleagues from CSE wish to add anything.