Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.RM-03 What else in your programme already covers this This control maps to 197 controls across 83 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CPS230-15 Operational Risk Elements of the Risk Management Framework CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-37 Service Provider Management Policy CPS230-46 Ongoing Risk Management of Each Material Arrangement CPS230-9 Management of the Full Range of Operational Risks CPS230-P18 Integration with the Risk Management Framework and Recovery Planning SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2) SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC9.1 CC9.1 Mitigating risks of business disruption 27557-1 Scope 27557-3 Terms and definitions 27557-6.4 Privacy risk treatment 27557-6.6 Recording and reporting 27557-7.3 Risk-based privacy program implementation 4.4 Business continuity management system 6.1.2 Addressing risks and opportunities 8.2.3 Risk assessment 8.4.1 General 5.2 Information security roles and responsibilities 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 5.4 Management responsibilities 5.3.1 Leadership and commitment 5.4.1 Actions to address risks and opportunities 5.6.2 Information security risk assessment 5.7.3 Management review SASB-3 Leadership and Governance (LG) SASB-LG-2 Systemic Risk Management SASB-LG-3 Critical Incident Risk Management SASB-LG-5 Systemic Risk Management CPS220-04 Maintenance of a Risk Management Framework CPS220-07 Material Risk Categories the Framework Must Address CPS220-P22 Framework Structure for Managing Each Material Risk SPS220-18 Framework Coverage of All Material Risks SPS220-23 Risk Categories the Framework Must Cover SPS220-28 Annual Board Risk Management Declaration ISM-0726 Coordinating security risk management ISM-1918 CISO reporting to audit and risk committee ISM-1998 Integrating cyber security across business functions IS.D.OR.210 Information Security Risk Treatment IS.I.OR.210 Information Security Risk Treatment IS.I.OR.220 Information Security Risk Management FFIEC-03 Risk appetite and tolerance for IT risk FFIEC-18 Ongoing monitoring and assessment FFIEC-20 Exit strategy and transition planning CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) RA-3 Risk Assessment SR-2 Supply Chain Risk Management Plan (SR-2) CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) RA-3 Risk Assessment SR-2 Supply Chain Risk Management Plan (SR-2) 60601-1.4.1 General requirements 60601-1.4.2 Risk management process 60601-1.5.1 General requirements for testing IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62304-7.4 Risk Management of Software Changes 5.2 Information security roles and responsibilities 5.35 Independent review of information security 5.4 Management responsibilities ISO23894-5.1 Leadership and Commitment ISO23894-5.2 AI Risk Management Integration ISO23894-5.5 Framework Evaluation NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System) NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF PCI-P2PE-16 Due diligence and onboarding PCI-P2PE-18 Ongoing monitoring and assessment PCI-P2PE-19 Concentration risk management PCI-PIN-16 Due diligence and onboarding PCI-PIN-18 Ongoing monitoring and assessment PCI-PIN-19 Concentration risk management PCI-SSF-03 Risk appetite and tolerance for IT risk PCI-SSF-16 Due diligence and onboarding PCI-SSF-17 Contractual security requirements SOC-CY-DC1 Nature of Business and Operations SOC-CY-DC3 Cybersecurity Risk Management Objectives SOC-CY-DC4 Governance Structure SOCI-S30AC Obligation to adopt a CIRMP SOCI-S30AD Compliance with CIRMP SOCI-S30AE Annual review of CIRMP SII-P2-11 Remuneration Policy SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance CPS234-16 Assessment of Related Party and Third Party Capability CPS234-20 Information Asset Classification BS65000-RM-01 Resilience Journey BS65000-RM-02 Integrated Approach CAT-D1-2 Risk management CAT-ML-2 Evolving ICP-16 Enterprise Risk Management for Solvency Purposes ICP-8 Risk Management and Internal Controls ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.3 Information security risk treatment 4.4 AI management system A.2.3 Alignment with other organizational policies NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-4 Third-Party Risk Management and Cloud PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs AMLCTF-82 Part A Compliance API1164-21 TSA Pipeline Security Directive Alignment AS9100D-8.1 Operational Planning and Control P1-S2 Risk-Management Systems CFTC-SS-2 Enterprise Risk Management and Governance Category ITSG33-RMP-4 Security Control Selection and Profiles (Annex 4A) CJIS-19 Supply Chain Risk Management IEC62443-21 Supply chain risk management for critical components ISO-15189-5.6 Risk management ISO-20400-4.5 Key considerations for sustainable procurement ISO-22320-4.3 Risk-based approach ISO28001-SA-04 Security Risk Treatment Planning ISO27019-21 Supply chain risk management for critical components Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation ID.GV-4 ID.GV-4: Governance and risk management processes address cybersecurity risks ID.GV-4 ID.GV-4: Governance and risk management processes address cybersecurity risks GV.RM-03 GV.RM-03 Incident decisions informed by enterprise risk, not cybersecurity risk alone NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NZISM-1 NZISM Governance, Documentation, and Classification System ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework 12.1.1 12.1.1 Overall information security policy established and disseminated PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management SECCLIM-2 Risk Management: Identification, Assessment, Integration SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management AIGF-1.1 Risk Management and Internal Controls IM8-TPM.4 Supply Chain Risk Management ISMSP-MS-02 Risk Management TSSR-SEC-3 National Security Risk Management CRM-3 Risk Management Framework UKAI-1 Risk-Based Approach and Pro-Innovation Principles Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.