Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.PO-01 NIST Cybersecurity Framework 2.0
GV - Govern
NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 143 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CCM-A&A-01 Audit and Assurance Policy and Procedures CCM-AIS-01 Application and Interface Security Policy and Procedures CCM-CEK-01 Encryption and Key Management Policy and Procedures CCM-DSP-01 Security and Privacy Policy and Procedures CCM-GRC-01 Governance Program Policy and Procedures CCM-GRC-05 Information Security Program CCM-IAM-01 Identity and Access Management Policy and Procedures CCM-IPY-01 Interoperability and Portability Policy and Procedures CCM-IVS-01 Infrastructure and Virtualization Security Policy and Procedures CCM-LOG-01 Logging and Monitoring Policy and Procedures CCM-TVM-01 Threat and Vulnerability Management Policy and Procedures 1.1.1 1.1.1 Requirement 1 policies and procedures governed 11.1.1 11.1.1 Requirement 11 policies and procedures managed 12.1.1 12.1.1 Overall information security policy established and disseminated 2.1.1 2.1.1 Requirement 2 policies and procedures governed 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated 7.1.1 7.1.1 Requirement 7 policies and procedures maintained 9.1.1 9.1.1 Requirement 9 policies and procedures maintained 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use 8.1.1 8.1.1 Requirement 8 policies and procedures maintained 4.4 AI management system 5.1 Leadership and commitment 5.2 AI policy 6.2 AI objectives and planning to achieve them 7.5 Documented information A.2 Policies related to AI A.2.2 AI policy A.2.3 Alignment with other organizational policies A.6.1.2 Objectives for responsible development of AI system A.9.2 Processes for responsible use of AI systems 5.1 General 5.3 Leadership 5.3.1 Leadership and commitment 5.3.2 Policy 6.1 General 6.2 Information security policies 6.2.1 Management direction for information security 6.3.1 Internal organization 8.2.2 Organization’s purposes C5-AM-02 Acceptable Use and Safe Handling of Assets Policy C5-COM-02 Policy for planning and conducting audits C5-OIS-02 Information Security Policy C5-OIS-06 Risk Management Policy C5-SP-01 Documentation, communication and provision of policies and instructions CIS-15.2 Establish and Maintain a Service Provider Management Policy CIS-15.4 Ensure Service Provider Contracts Include Security Requirements CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-3.7 Establish and Maintain a Data Classification Scheme CIS-7.1 Establish and Maintain a Vulnerability Management Process SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2) SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) SOC2-P4.1 P4.1 Limiting use to identified purposes CPS220-05 Risk Management Strategy CPS220-P23 Minimum Contents of the Risk Management Framework CPS220-P30 Minimum Contents of the Risk Management Strategy CPS220-P35 Required Content of Risk Management Policies and Procedures ASBv3-GS-3 Define and implement data protection strategy ASBv3-GS-4 Define and implement network security strategy ASBv3-GS-5 Define and implement security posture management strategy ASBv3-GS-6 Define and implement identity and privileged access strategy PL-1 Policy and Procedures RA-1 Policy and Procedures SI-1 Policy and Procedures SR-1 Policy and Procedures (SR-1) PL-1 Policy and Procedures RA-1 Policy and Procedures SI-1 Policy and Procedures SR-1 Policy and Procedures (SR-1) 4.4 Business continuity management system 5.2 Policy 5.2.1 Establishing the business continuity policy 6.2.1 Establishing business continuity objectives ADMF-2.1 Leadership commitment in policy (who) ADMF-2.3 Establish the data management approach (how) ADMF-2.4 Embed data management in corporate governance and policy CPS230-15 Operational Risk Elements of the Risk Management Framework CPS230-37 Service Provider Management Policy SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls SPS220-P9 Board Approval of Group Policies and Functions AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-7 Generally Accepted Standards and Best Practices 5.1 Policies for information security 8.3 Information access restriction 5.1 Policies for information security 5.4 Management responsibilities CPS234-19 Information Security Policy Framework ISM-0047 CISO and authorising officer document approvals BE-CF-35 Cybersecurity governance and policy Art.21.2.a Policies on risk analysis and on information system security ID.GV-1 ID.GV-1: Organizational information security policy is established ID.GV-1 ID.GV-1: Organizational cybersecurity policy is established and communicated Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 143 it maps to, and the evidence behind each claim, over MCP and REST.