NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-02: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 39 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 42001:2023 · 6 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.3 Determining the scope of the AI management system
  • A.5.2 AI system impact assessment process
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.8 Information for interested parties of AI systems

ISO 22301:2019 · 5 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.2.1 General
  • 4.2.2 Legal and regulatory requirements
  • 4.3 Determining the scope of the business continuity management system

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

ISO 27701:2019 · 3 controls

  • 5.2 Context of the organization
  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.2.3 Determining the scope of the information security management system
  • CPS220-17 Group Framework Coverage of Non Regulated Group Entities
  • CPS220-P28 Minimum Contents of the Risk Appetite Statement

CIS Controls v8 · 2 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-15.1 Establish and Maintain an Inventory of Service Providers

HIPAA Security Rule · 2 controls

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)
  • ID.GV-2 ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
  • ID.SC-2 ID.SC-2: Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process
  • CPS230-P28 Risk Assessment Before Providing a Material Service to Another Party
  • MYHR-GOV-1 System Operator functions and oversight
  • ISM-1602 Communication of cyber security documentation

C5 (Germany) · 1 control

  • ID.GV-2 ID.GV-2: Information security roles & responsibilities are coordinated and aligned with internal roles and external partners
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.