NIST Cybersecurity Framework 1.1 ID.GV-1: ID.GV-1: Organizational cybersecurity policy is established and communicated
Organizational cybersecurity policy is established and communicated. IDENTIFY (ID) Function, Governance (ID.GV) Category. Outcome in the Framework Core of Version 1.1; withdrawn in CSF 2.0 (incorporated into GV.PO-01, GV.PO-02, GV.PO).
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission