Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.OC-03 NIST Cybersecurity Framework 2.0
GV - Govern
NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-03: Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 125 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.2 Context of the organization 5.2.3 Determining the scope of the information security management system 6.15 Compliance 6.15.1 Compliance with legal and contractual requirements 7.2.2 Identify lawful basis 7.2.5 Privacy impact assessment 7.2.8 Records related to processing PII 7.3.1 Determining and fulfilling obligations to PII principals 7.5 PII sharing, transfer, and disclosure 7.5.1 Identify basis for PII transfer between jurisdictions 8.2.5 Customer obligations 8.5.4 Notification of PII disclosure requests 8.5.5 Legally binding PII disclosures CPS220-19 APRA Notification of Framework Breach within 10 Business Days CPS220-P35 Required Content of Risk Management Policies and Procedures CPS220-P43 Designated Compliance Function CPS220-P51 Submission Deadline for the Risk Management Declaration CPS220-P52 Submission of Appetite Statement, Business Plan and Strategy to APRA CPS220-P54 APRA Notification of Material Changes to the Institution CPS220-P55 APRA Notification of Overseas Business Rights 4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.2.2 Legal and regulatory requirements 4.3 Determining the scope of the business continuity management system 4.3.2 Scope of the business continuity management system 8.4.1 General 4.1 Understanding the organization and its context 4.2 Understanding the needs and expectations of interested parties 4.3 Determining the scope of the AI management system 6.1.4 AI system impact assessment 8.2 AI risk assessment A.9 Use of AI systems APPI-A18 Restriction on Handling Beyond the Purpose of Use APPI-A23 Security Control Measures APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A27 Restriction on Provision to Third Parties APPI-A28 Provision to Third Parties in Foreign Countries CPS230-45 APRA Access Provisions in Formal Agreements CPS230-9 Management of the Full Range of Operational Risks CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours CPS230-P51 Annual Submission of the Material Service Provider Register to APRA CPS230-P59 APRA Notification of Service Agreements and Offshoring CFTC-SS-19 Prompt Notification to the Commission CFTC-SS-20 Production of System Safeguards Books and Records CFTC-SS-39 Critical Financial Market Designation Obligations CFTC-SS-7 Generally Accepted Standards and Best Practices CM-10 Software Usage Restrictions PL-1 Policy and Procedures SA-4 Acquisition Process SI-12 Information Management and Retention CM-10 Software Usage Restrictions PL-1 Policy and Procedures SA-4 Acquisition Process SI-12 Information Management and Retention 5.20 Addressing information security within supplier agreements 5.31 Legal, statutory, regulatory and contractual requirements 5.34 Privacy and protection of PII 5.5 Contact with authorities Art.24 Use certified ICT products, services and processes where the Member State requires it Art.26 Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union Art.3.4 Submit and maintain entity registration information with the competent authority Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence 12.1.1 12.1.1 Overall information security policy established and disseminated 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.5.2 12.5.2 Annual and change-driven scope confirmation 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility SPS220-44 APRA Notification of Framework Breach within 10 Business Days SPS220-P33 Submission Deadline for the Risk Management Declaration SPS220-P36 APRA Notification of Material Changes to Business Operations C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements C5-INQ-01 Legal Assessment of Investigative Inquiries C5-PSS-12 Locations of Data Processing and Storage 5.31 Legal, statutory, regulatory and contractual requirements 5.32 Intellectual property rights 5.34 Privacy and protection of personal identifiable information (PII) SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15) SOC2-P4.1 P4.1 Limiting use to identified purposes CPS234-35 APRA Notification of Material Incidents within 72 Hours CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days SEC01-BP03 Identify and validate control objectives SEC07-BP01 Understand your data classification scheme ISM-1478 Oversight of cyber security program and compliance ISM-2002 Board cyber security literacy ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-LT-6 Configure log storage retention CIS-15.3 Classify Service Providers CIS-17.4 Establish and Maintain an Incident Response Process GDPR-Art.24 Responsibility of the controller GDPR-Art.5 Principles relating to processing of personal data DE.DP-2 DE.DP-2: Detection activities comply with all applicable requirements ID.GV-3 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed DE.DP-2 DE.DP-2: Detection activities comply with all applicable requirements ID.GV-3 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed SEC-CYB-03 National Security or Public Safety Delay Coordination SEC-CYB-17 Coordination with Other Regulatory Notifications ANSSI-HYG-02 Raise User Awareness of Basic Security Practice AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data AEO-2 Demonstrated Compliance with Customs Requirements 03.14.08 Information Management and Retention GV.OC-03 GV.OC-03 Legal, regulatory and contractual requirements include incident response requirements Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.