NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-04: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 65 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 9 controls

  • 4.1 Understanding the organization and its context
  • 4.3 Determining the scope of the business continuity management system
  • 4.3.1 General
  • 4.3.2 Scope of the business continuity management system
  • 6.2.1 Establishing business continuity objectives
  • 6.2.2 Determining business continuity objectives
  • 8.2 Business impact analysis and risk assessment
  • 8.2.2 Business impact analysis
  • 8.3 Business continuity strategies and solutions

ISO 27701:2019 · 7 controls

  • 5.2 Context of the organization
  • 5.2.1 Understanding the organization and its context
  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.2.3 Determining the scope of the information security management system
  • 5.4.2 Information security objectives and planning to achieve them
  • 6.5.1 Responsibility for assets
  • 8.2.2 Organization’s purposes

ISO 27001:2022 · 6 controls

  • 5.12 Classification of information
  • 5.29 Information security during disruption
  • 5.30 ICT readiness for business continuity
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.9 Inventory of information and other associated assets
  • 8.13 Information backup

FedRAMP High · 5 controls

  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-7 Risk Response
  • RA-9 Criticality Analysis (RA-9)
  • SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3))

FedRAMP Moderate · 4 controls

  • CP-2 Contingency Plan
  • CP-2(8) Contingency Plan | Identify Critical Assets (CP-2(8))
  • RA-9 Criticality Analysis (RA-9)
  • SA-15(3) Development Process, Standards, and Tools | Criticality Analysis (SA-15(3))

NIST SP 800-53 Rev 5 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
  • CPS230-17 Mandatory Minimum Classification of Critical Operations
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPS230-P40 Required Content of the Business Continuity Plan

ISO/IEC 42001:2023 · 3 controls

  • 4.1 Understanding the organization and its context
  • 4.3 Determining the scope of the AI management system
  • A.6.1.2 Objectives for responsible development of AI system
  • ISM-1633 System boundary, criticality and objectives
  • ISM-2005 Understanding critical business assets

HIPAA Security Rule · 2 controls

  • ID.BE-4 ID.BE-4: Dependencies and critical functions for delivery of critical services are established
  • ID.BE-5 ID.BE-5: Resilience requirements to support delivery of critical services are established
  • ID.BE-4 ID.BE-4: Dependencies and critical functions for delivery of critical services are established
  • ID.BE-5 ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations)

NIST SP 800-66 Rev 2 · 2 controls

APRA CPS 234 · 1 control

C5 (Germany) · 1 control

  • C5-BCM-02 Business impact analysis policies and instructions
  • CFTC-SS-23 Resources Sufficient to Fulfil Obligations

ISO 27002:2022 · 1 control

  • 5.30 ICT readiness for business continuity

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • GV.OC-04 GV.OC-04 External dependencies on the organization inform response priorities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OC-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 65 it maps to, and the evidence behind each claim, over MCP and REST.