NIST Cybersecurity Framework 1.0 ID.GV-1: ID.GV-1: Organizational information security policy is established
Organizational information security policy is established. IDENTIFY (ID) Function, Governance (ID.GV) Category. Outcome in the Framework Core of Version 1.0; reworded in Version 1.1 as: "Organizational cybersecurity policy is established and communicated".
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission