NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-02: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 133 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 17 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PS-1 Policy and Procedures
  • PS-8 Personnel Sanctions
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 17 controls

  • AC-1 Policy and Procedures
  • AT-1 Policy and Procedures
  • AU-1 Policy and Procedures
  • CA-1 Policy and Procedures
  • CM-1 Policy and Procedures
  • CP-1 Policy and Procedures
  • IA-1 Policy and Procedures
  • MA-1 Policy and Procedures
  • MP-1 Policy and Procedures
  • PE-1 Policy and Procedures
  • PL-1 Policy and Procedures
  • PS-1 Policy and Procedures
  • PS-8 Personnel Sanctions
  • RA-1 Policy and Procedures
  • SC-1 Policy and Procedures
  • SI-1 Policy and Procedures
  • SR-1 Policy and Procedures (SR-1)

PCI DSS 4.0 · 15 controls

  • 1.1.1 1.1.1 Requirement 1 policies and procedures governed
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 4.1.1 4.1.1 Requirement 4 policies and procedures maintained and communicated
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 7.1.1 7.1.1 Requirement 7 policies and procedures maintained
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

NIST SP 800-53 Rev 5 · 10 controls

ISO 22301:2019 · 7 controls

  • 5.1 Leadership and commitment
  • 5.2 Policy
  • 5.2.1 Establishing the business continuity policy
  • 5.2.2 Communicating the business continuity policy
  • 7.5.3 Control of documented information
  • 9.3 Management review
  • 9.3.1 General

HIPAA Security Rule · 6 controls

ISO 27001:2022 · 6 controls

  • 5.1 Policies for information security
  • 5.10 Acceptable use of information and other associated assets
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities
  • 6.3 Information security awareness, education and training

ISO 27701:2019 · 6 controls

  • 5.3.2 Policy
  • 5.5.4 Communication
  • 5.5.5 Documented information
  • 5.7.3 Management review
  • 6.2 Information security policies
  • 6.2.1 Management direction for information security

ISO/IEC 42001:2023 · 6 controls

  • 5.2 AI policy
  • 7.4 Communication
  • 7.5.3 Control of documented information
  • 9.3 Management review
  • A.2.2 AI policy
  • A.2.4 Review of the AI policy

ISO 27002:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.10 Acceptable use of information and other associated assets
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

NIST SP 800-66 Rev 2 · 4 controls

  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • CPS220-P36 Monitoring of Policy Review Dates and Ownership
  • ISM-0888 Annual review and currency statements
  • ISM-1478 Oversight of cyber security program and compliance
  • ISM-1602 Communication of cyber security documentation

C5 (Germany) · 3 controls

  • C5-OIS-02 Information Security Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-02 Review and Approval of Policies and Instructions

CIS Controls v8 · 3 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-8.1 Establish and Maintain an Audit Log Management Process

SOC 2 · 3 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

APRA CPS 234 · 2 controls

  • CPS234-19 Information Security Policy Framework
  • CPS234-P19 Policy Direction to All Responsible Parties
  • ADMF-2.4 Embed data management in corporate governance and policy
  • ADMF-6.5 Update policies, procedures and processes
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies
  • CPS230-24 Design and Embedding of Internal Controls
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • PV-2 Audit and enforce secure configurations
  • CFTC-SS-32 Timely Advance Notice of Material Planned Changes

CMMC 2.0 · 1 control

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security
  • ID.GV-1 ID.GV-1: Organizational information security policy is established
  • ID.GV-1 ID.GV-1: Organizational cybersecurity policy is established and communicated

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.PO-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 133 it maps to, and the evidence behind each claim, over MCP and REST.