NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 197 controls across 83 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-9 Management of the Full Range of Operational Risks
  • CPS230-P18 Integration with the Risk Management Framework and Recovery Planning

SOC 2 · 6 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

CMMC 2.0 · 4 controls

ISO 22301:2019 · 4 controls

  • 4.4 Business continuity management system
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 8.4.1 General

ISO 27002:2022 · 4 controls

  • 5.2 Information security roles and responsibilities
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

ISO 27701:2019 · 4 controls

  • 5.3.1 Leadership and commitment
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.7.3 Management review

SASB Standards · 4 controls

  • SASB-3 Leadership and Governance (LG)
  • SASB-LG-2 Systemic Risk Management
  • SASB-LG-3 Critical Incident Risk Management
  • SASB-LG-5 Systemic Risk Management
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-07 Material Risk Categories the Framework Must Address
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • SPS220-18 Framework Coverage of All Material Risks
  • SPS220-23 Risk Categories the Framework Must Cover
  • SPS220-28 Annual Board Risk Management Declaration
  • ISM-0726 Coordinating security risk management
  • ISM-1918 CISO reporting to audit and risk committee
  • ISM-1998 Integrating cyber security across business functions
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

FedRAMP High · 3 controls

  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • RA-3 Risk Assessment
  • SR-2 Supply Chain Risk Management Plan (SR-2)

FedRAMP Moderate · 3 controls

  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • RA-3 Risk Assessment
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO 27001:2022 · 3 controls

  • 5.2 Information security roles and responsibilities
  • 5.35 Independent review of information security
  • 5.4 Management responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

PCI P2PE · 3 controls

  • PCI-P2PE-16 Due diligence and onboarding
  • PCI-P2PE-18 Ongoing monitoring and assessment
  • PCI-P2PE-19 Concentration risk management

PCI PIN Security · 3 controls

  • PCI-PIN-16 Due diligence and onboarding
  • PCI-PIN-18 Ongoing monitoring and assessment
  • PCI-PIN-19 Concentration risk management

PCI SSF · 3 controls

  • PCI-SSF-03 Risk appetite and tolerance for IT risk
  • PCI-SSF-16 Due diligence and onboarding
  • PCI-SSF-17 Contractual security requirements
  • SOC-CY-DC1 Nature of Business and Operations
  • SOC-CY-DC3 Cybersecurity Risk Management Objectives
  • SOC-CY-DC4 Governance Structure
  • SOCI-S30AC Obligation to adopt a CIRMP
  • SOCI-S30AD Compliance with CIRMP
  • SOCI-S30AE Annual review of CIRMP

Solvency II · 3 controls

  • SII-P2-11 Remuneration Policy
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 42001:2023 · 2 controls

  • 4.4 AI management system
  • A.2.3 Alignment with other organizational policies

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • ITSG33-RMP-4 Security Control Selection and Profiles (Annex 4A)

DORA · 1 control

  • CJIS-19 Supply Chain Risk Management

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • ID.GV-4 ID.GV-4: Governance and risk management processes address cybersecurity risks
  • ID.GV-4 ID.GV-4: Governance and risk management processes address cybersecurity risks

NIST SP 1800-32 · 1 control

  • GV.RM-03 GV.RM-03 Incident decisions informed by enterprise risk, not cybersecurity risk alone
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework

PCI DSS 4.0 · 1 control

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • TSSR-SEC-3 National Security Risk Management
  • CRM-3 Risk Management Framework
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.