NIST Cybersecurity Framework 2.0
Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OV-02: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 6 controls

  • 10.1 Nonconformity and corrective action
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 9.3 Management review
  • 9.3.2 Management review input
  • 9.3.3 Management review outputs

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P46 Scope of the Comprehensive Review
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle

ISO 27701:2019 · 4 controls

  • 5.2.1 Understanding the organization and its context
  • 5.4.1 Actions to address risks and opportunities
  • 5.7.3 Management review
  • 6.15.2 Information security reviews

ISO/IEC 42001:2023 · 4 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 9.3 Management review
  • 9.3.2 Management review inputs
  • SPS220-46 Triennial Comprehensive Review of the Framework
  • SPS220-P28 Annual Review in Non Comprehensive Review Years
  • SPS220-P29 Scope and Minimum Content of the Comprehensive Review

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • ISM-0888 Annual review and currency statements
  • ISM-1617 Review and update of cyber security program

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • RA-1 Policy and Procedures

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • RA-1 Policy and Procedures

PCI DSS 4.0 · 2 controls

  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • CPS230-66 Review of Operational Risk Management
  • ADMF-6.3 Review categories assigned to datasets

C5 (Germany) · 1 control

  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures

DORA · 1 control

ISO 27001:2022 · 1 control

  • 5.35 Independent review of information security

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • GV.OV-02 GV.OV-02 Risks from past incidents considered when reviewing the strategy

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.OV-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.