NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders

Risk management objectives are established and agreed to by organizational stakeholders

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 90 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 11 controls

ISO 27701:2019 · 7 controls

  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.2.4 Information security management system
  • 5.3.2 Policy
  • 5.4 Planning
  • 5.4.2 Information security objectives and planning to achieve them
  • 5.7.3 Management review
  • 8.2.2 Organization’s purposes

ISO/IEC 42001:2023 · 6 controls

  • 5.2 AI policy
  • 6.1.1 General
  • 6.2 AI objectives and planning to achieve them
  • 9.3 Management review
  • A.6.1.2 Objectives for responsible development of AI system
  • A.9.3 Objectives for responsible use of AI system

ISO 22301:2019 · 5 controls

  • 5.1 Leadership and commitment
  • 6.2 Business continuity objectives and planning to achieve them
  • 6.2.1 Establishing business continuity objectives
  • 6.2.2 Determining business continuity objectives
  • 8.3 Business continuity strategies and solutions

ISO 27001:2022 · 5 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.35 Independent review of information security
  • 5.4 Management responsibilities
  • CPS220-02 Board Responsibility for the Risk Management Framework
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-05 Risk Management Strategy
  • CPS220-P33 Risks Arising from Strategic Objectives and the Business Plan

C2M2 · 3 controls

  • PROGRAM-1 Establish and Maintain the Cybersecurity Program
  • RISK-1 Establish a Cyber Risk Management Strategy and Program
  • RISK-3 Manage and Respond to Cyber Risk

FedRAMP High · 3 controls

  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • RA-1 Policy and Procedures
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))

FedRAMP Moderate · 3 controls

  • CP-6(3) Alternate Storage Site | Accessibility (CP-6(3))
  • RA-1 Policy and Procedures
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))

HIPAA Security Rule · 3 controls

  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • ADMF-1.4 Risk management function responsibilities
  • ADMF-2.2 Define objectives, scope and considerations (what and why)
  • AESCSF-CPM-2 Cyber security governance and strategy
  • AESCSF-RM-1 Establish cyber security risk management strategy
  • BMA-2 Proportionality Principle
  • BMA-3 Operational Cyber Risk Management Programme

C5 (Germany) · 2 controls

  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

DORA · 2 controls

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.4 Management responsibilities

NIST SP 800-66 Rev 2 · 2 controls

PCI DSS 4.0 · 2 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • SPS220-17 Maintenance of a Risk Management Framework
  • ASIC-CR-GOV-2 Treat cyber resilience as a management and investment tool

BCBS 239 · 1 control

  • BCBS239-P1 Governance
  • BE-CF-43 Assurance level selection and scoping
  • ITSG33-RMP-1 Departmental IT Security Risk Management Activities (Annex 1)
  • DSL-Art27 Data Security Management System and Whole-Lifecycle Measures (Art. 27)
  • PIPL-Art9 Security Responsibility of Handlers
  • CDMC-KC1 Data Control Compliance
  • DCAM-4.1 Data Governance Operating Model

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
  • ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
  • SECCYB-2 Risk Management Processes (Item 106(b))

SOC 2 · 1 control

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.