NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-02: Risk appetite and risk tolerance statements are established, communicated, and maintained

Risk appetite and risk tolerance statements are established, communicated, and maintained

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 6 controls

  • 5.2.1 Establishing the business continuity policy
  • 6.1 Actions to address risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 6.2.1 Establishing business continuity objectives
  • 6.2.2 Determining business continuity objectives
  • 8.2.3 Risk assessment

ISO/IEC 42001:2023 · 5 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.3 AI risk treatment
  • 6.1.4 AI system impact assessment
  • A.5.2 AI system impact assessment process
  • A.5.4 Assessing AI system impact on individuals or groups of individuals

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC3.3 CC3.3 Considering fraud risk (COSO principle 8)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CPS220-06 Risk Appetite Statement
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P28 Minimum Contents of the Risk Appetite Statement
  • CPS220-P52 Submission of Appetite Statement, Business Plan and Strategy to APRA

ISO 27701:2019 · 4 controls

  • 5.3.2 Policy
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.3 Information security risk treatment
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • CPS230-8 Board Oversight, Approval of the BCP, Tolerance Levels and Service Provider Policy
  • SPS220-19 Risk Appetite Statement
  • SPS220-42 Minimum Contents of the Risk Management Framework
  • SPS220-P20 Minimum Contents of the Risk Appetite Statement

FedRAMP High · 3 controls

  • PS-2 Position Risk Designation
  • RA-2 Security Categorization
  • RA-3 Risk Assessment

FedRAMP Moderate · 3 controls

  • PS-2 Position Risk Designation
  • RA-2 Security Categorization
  • RA-3 Risk Assessment
  • ID.RM-2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed
  • ID.RM-3 ID.RM-3: The organization's determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
  • ID.RM-2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed
  • ID.RM-3 ID.RM-3: The organization's determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis

PCI DSS 4.0 · 2 controls

  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency

APRA CPS 234 · 1 control

  • ADMF-1.5 Executive direction and risk appetite
  • ISM-0009 Identifying supplementary controls

C5 (Germany) · 1 control

  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • ITSG33-RMP-2 Information System Security Risk Management Activities / ISSIP (Annex 2)

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.