Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.OC-01 What else in your programme already covers this This control maps to 59 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.3 Determining the scope of the business continuity management system 4.3.2 Scope of the business continuity management system 5.1 Leadership and commitment 6.1.1 Determining risks and opportunities 5.2 Context of the organization 5.2.1 Understanding the organization and its context 5.2.2 Understanding the needs and expectations of interested parties 5.2.3 Determining the scope of the information security management system 8.2.2 Organization’s purposes CPS220-P21 Consistency of the Framework with the Business Plan CPS220-P22 Framework Structure for Managing Each Material Risk CPS220-P31 Maintenance of a Business Plan CPS220-P33 Risks Arising from Strategic Objectives and the Business Plan 5.1 Policies for information security 5.2 Information security roles and responsibilities 5.31 Legal, statutory, regulatory and contractual requirements 5.7 Threat intelligence 4.1 Understanding the organization and its context 4.3 Determining the scope of the AI management system A.2.3 Alignment with other organizational policies A.5 Assessing impacts of AI systems SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2) SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3) SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) 5.1 Policies for information security 5.2 Information security roles and responsibilities 5.31 Legal, statutory, regulatory and contractual requirements SPS220-P13 Contagion Risk from Non Superannuation Business SPS220-P18 Risks Arising from Strategic Objectives and the Business Plan Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure Art.26 Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union ID.BE-2 ID.BE-2: The organization's place in critical infrastructure and its industry sector is identified and communicated ID.BE-3 ID.BE-3: Priorities for organizational mission, objectives, and activities are established and communicated ID.BE-2 ID.BE-2: The organization's place in critical infrastructure and its industry sector is identified and communicated ID.BE-3 ID.BE-3: Priorities for organizational mission, objectives, and activities are established and communicated CPS230-P26 Assessment of Business and Strategic Decisions on the Risk Profile ADMF-2.2 Define objectives, scope and considerations (what and why) SEC01-BP03 Identify and validate control objectives AWWA-1.1 Security Policy and Governance AESCSF-CPM-1 Cyber security program management ISM-1999 Aligning cyber strategy with business strategy C5-OIS-01 Information Security Management System (ISMS) PL-2 System Security and Privacy Plans PL-2 System Security and Privacy Plans Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.