NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 143 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 29 controls

  • CCM-A&A-01 Audit and Assurance Policy and Procedures
  • CCM-AIS-01 Application and Interface Security Policy and Procedures
  • CCM-CEK-01 Encryption and Key Management Policy and Procedures
  • CCM-DSP-01 Security and Privacy Policy and Procedures
  • CCM-GRC-01 Governance Program Policy and Procedures
  • CCM-GRC-05 Information Security Program
  • CCM-IAM-01 Identity and Access Management Policy and Procedures
  • CCM-IPY-01 Interoperability and Portability Policy and Procedures
  • CCM-IVS-01 Infrastructure and Virtualization Security Policy and Procedures
  • CCM-LOG-01 Logging and Monitoring Policy and Procedures
  • CCM-TVM-01 Threat and Vulnerability Management Policy and Procedures

PCI DSS 4.0 · 11 controls

  • 1.1.1 1.1.1 Requirement 1 policies and procedures governed
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

ISO/IEC 42001:2023 · 10 controls

  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 5.2 AI policy
  • 6.2 AI objectives and planning to achieve them
  • 7.5 Documented information
  • A.2 Policies related to AI
  • A.2.2 AI policy
  • A.2.3 Alignment with other organizational policies
  • A.6.1.2 Objectives for responsible development of AI system
  • A.9.2 Processes for responsible use of AI systems

ISO 27701:2019 · 9 controls

  • 5.1 General
  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.2 Policy
  • 6.1 General
  • 6.2 Information security policies
  • 6.2.1 Management direction for information security
  • 6.3.1 Internal organization
  • 8.2.2 Organization’s purposes

C5 (Germany) · 5 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-COM-02 Policy for planning and conducting audits
  • C5-OIS-02 Information Security Policy
  • C5-OIS-06 Risk Management Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions

CIS Controls v8 · 5 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-3.7 Establish and Maintain a Data Classification Scheme
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process

SOC 2 · 5 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • CPS220-05 Risk Management Strategy
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • ASBv3-GS-3 Define and implement data protection strategy
  • ASBv3-GS-4 Define and implement network security strategy
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-GS-6 Define and implement identity and privileged access strategy

FedRAMP High · 4 controls

  • PL-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 4 controls

  • PL-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

HIPAA Security Rule · 4 controls

ISO 22301:2019 · 4 controls

  • 4.4 Business continuity management system
  • 5.2 Policy
  • 5.2.1 Establishing the business continuity policy
  • 6.2.1 Establishing business continuity objectives
  • ADMF-2.1 Leadership commitment in policy (who)
  • ADMF-2.3 Establish the data management approach (how)
  • ADMF-2.4 Embed data management in corporate governance and policy

NIST SP 800-66 Rev 2 · 3 controls

  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-37 Service Provider Management Policy
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • SPS220-P9 Board Approval of Group Policies and Functions
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

ISO 27001:2022 · 2 controls

  • 5.1 Policies for information security
  • 8.3 Information access restriction

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.4 Management responsibilities

NIST SP 800-161 Rev 1 · 2 controls

APRA CPS 234 · 1 control

  • CPS234-19 Information Security Policy Framework
  • ISM-0047 CISO and authorising officer document approvals
  • BE-CF-35 Cybersecurity governance and policy

CMMC 2.0 · 1 control

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security
  • ID.GV-1 ID.GV-1: Organizational information security policy is established
  • ID.GV-1 ID.GV-1: Organizational cybersecurity policy is established and communicated

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 143 it maps to, and the evidence behind each claim, over MCP and REST.