Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.RM-01 What else in your programme already covers this This control maps to 90 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.2.2 Understanding the needs and expectations of interested parties 5.2.4 Information security management system 5.3.2 Policy 5.4 Planning 5.4.2 Information security objectives and planning to achieve them 5.7.3 Management review 8.2.2 Organization’s purposes 5.2 AI policy 6.1.1 General 6.2 AI objectives and planning to achieve them 9.3 Management review A.6.1.2 Objectives for responsible development of AI system A.9.3 Objectives for responsible use of AI system 5.1 Leadership and commitment 6.2 Business continuity objectives and planning to achieve them 6.2.1 Establishing business continuity objectives 6.2.2 Determining business continuity objectives 8.3 Business continuity strategies and solutions 5.1 Policies for information security 5.2 Information security roles and responsibilities 5.31 Legal, statutory, regulatory and contractual requirements 5.35 Independent review of information security 5.4 Management responsibilities CPS220-02 Board Responsibility for the Risk Management Framework CPS220-04 Maintenance of a Risk Management Framework CPS220-05 Risk Management Strategy CPS220-P33 Risks Arising from Strategic Objectives and the Business Plan PROGRAM-1 Establish and Maintain the Cybersecurity Program RISK-1 Establish a Cyber Risk Management Strategy and Program RISK-3 Manage and Respond to Cyber Risk CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) RA-1 Policy and Procedures SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1)) CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) RA-1 Policy and Procedures SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1)) CPS230-15 Operational Risk Elements of the Risk Management Framework CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers ADMF-1.4 Risk management function responsibilities ADMF-2.2 Define objectives, scope and considerations (what and why) AESCSF-CPM-2 Cyber security governance and strategy AESCSF-RM-1 Establish cyber security risk management strategy BMA-2 Proportionality Principle BMA-3 Operational Cyber Risk Management Programme CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-2 Enterprise Risk Management and Governance Category 5.1 Policies for information security 5.4 Management responsibilities 12.1.1 12.1.1 Overall information security policy established and disseminated 12.1.2 12.1.2 Security policy reviewed annually and updated as needed SPS220-17 Maintenance of a Risk Management Framework ASIC-CR-GOV-2 Treat cyber resilience as a management and investment tool BE-CF-43 Assurance level selection and scoping ITSG33-RMP-1 Departmental IT Security Risk Management Activities (Annex 1) DSL-Art27 Data Security Management System and Whole-Lifecycle Measures (Art. 27) PIPL-Art9 Security Responsibility of Handlers CDMC-KC1 Data Control Compliance DCAM-4.1 Data Governance Operating Model Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders SECCYB-2 Risk Management Processes (Item 106(b)) SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.