NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-03: Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 125 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 13 controls

  • 5.2 Context of the organization
  • 5.2.3 Determining the scope of the information security management system
  • 6.15 Compliance
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.2.2 Identify lawful basis
  • 7.2.5 Privacy impact assessment
  • 7.2.8 Records related to processing PII
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 8.2.5 Customer obligations
  • 8.5.4 Notification of PII disclosure requests
  • 8.5.5 Legally binding PII disclosures
  • CPS220-19 APRA Notification of Framework Breach within 10 Business Days
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS220-P43 Designated Compliance Function
  • CPS220-P51 Submission Deadline for the Risk Management Declaration
  • CPS220-P52 Submission of Appetite Statement, Business Plan and Strategy to APRA
  • CPS220-P54 APRA Notification of Material Changes to the Institution
  • CPS220-P55 APRA Notification of Overseas Business Rights

ISO 22301:2019 · 6 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.2.2 Legal and regulatory requirements
  • 4.3 Determining the scope of the business continuity management system
  • 4.3.2 Scope of the business continuity management system
  • 8.4.1 General

ISO/IEC 42001:2023 · 6 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.3 Determining the scope of the AI management system
  • 6.1.4 AI system impact assessment
  • 8.2 AI risk assessment
  • A.9 Use of AI systems

NIST SP 800-53 Rev 5 · 6 controls

APPI · 5 controls

  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A23 Security Control Measures
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A28 Provision to Third Parties in Foreign Countries
  • CPS230-45 APRA Access Provisions in Formal Agreements
  • CPS230-9 Management of the Full Range of Operational Risks
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P51 Annual Submission of the Material Service Provider Register to APRA
  • CPS230-P59 APRA Notification of Service Agreements and Offshoring
  • CFTC-SS-19 Prompt Notification to the Commission
  • CFTC-SS-20 Production of System Safeguards Books and Records
  • CFTC-SS-39 Critical Financial Market Designation Obligations
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

FedRAMP High · 4 controls

  • CM-10 Software Usage Restrictions
  • PL-1 Policy and Procedures
  • SA-4 Acquisition Process
  • SI-12 Information Management and Retention

FedRAMP Moderate · 4 controls

  • CM-10 Software Usage Restrictions
  • PL-1 Policy and Procedures
  • SA-4 Acquisition Process
  • SI-12 Information Management and Retention

HIPAA Security Rule · 4 controls

ISO 27002:2022 · 4 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 5.5 Contact with authorities

NIS2 Directive · 4 controls

  • Art.24 Use certified ICT products, services and processes where the Member State requires it
  • Art.26 Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union
  • Art.3.4 Submit and maintain entity registration information with the competent authority
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • SPS220-44 APRA Notification of Framework Breach within 10 Business Days
  • SPS220-P33 Submission Deadline for the Risk Management Declaration
  • SPS220-P36 APRA Notification of Material Changes to Business Operations

C5 (Germany) · 3 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-INQ-01 Legal Assessment of Investigative Inquiries
  • C5-PSS-12 Locations of Data Processing and Storage

DORA · 3 controls

ISO 27001:2022 · 3 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.32 Intellectual property rights
  • 5.34 Privacy and protection of personal identifiable information (PII)

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P4.1 P4.1 Limiting use to identified purposes

APRA CPS 234 · 2 controls

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • SEC01-BP03 Identify and validate control objectives
  • SEC07-BP01 Understand your data classification scheme
  • ISM-1478 Oversight of cyber security program and compliance
  • ISM-2002 Board cyber security literacy
  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-LT-6 Configure log storage retention

CIS Controls v8 · 2 controls

  • CIS-15.3 Classify Service Providers
  • CIS-17.4 Establish and Maintain an Incident Response Process

GDPR · 2 controls

  • GDPR-Art.24 Responsibility of the controller
  • GDPR-Art.5 Principles relating to processing of personal data
  • DE.DP-2 DE.DP-2: Detection activities comply with all applicable requirements
  • ID.GV-3 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
  • DE.DP-2 DE.DP-2: Detection activities comply with all applicable requirements
  • ID.GV-3 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed
  • SEC-CYB-03 National Security or Public Safety Delay Coordination
  • SEC-CYB-17 Coordination with Other Regulatory Notifications
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • 03.14.08 Information Management and Retention

NIST SP 800-218 · 1 control

  • GV.OC-03 GV.OC-03 Legal, regulatory and contractual requirements include incident response requirements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 125 it maps to, and the evidence behind each claim, over MCP and REST.