NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-04: Strategic direction that describes appropriate risk response options is established and communicated

Strategic direction that describes appropriate risk response options is established and communicated

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 191 controls across 81 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

ISO/IEC 42001:2023 · 6 controls

  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 6.1.2 AI risk assessment
  • 6.2 AI objectives and planning to achieve them
  • 9.3 Management review
  • A.6.1.2 Objectives for responsible development of AI system
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-8 Board Oversight, Approval of the BCP, Tolerance Levels and Service Provider Policy
  • CPS230-P26 Assessment of Business and Strategic Decisions on the Risk Profile

ISO 22301:2019 · 5 controls

  • 5.1 Leadership and commitment
  • 5.2.1 Establishing the business continuity policy
  • 6.2.1 Establishing business continuity objectives
  • 8.3.2 Identification of strategies and solutions
  • 9.3.3 Management review outputs

ISO 27701:2019 · 5 controls

  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.2 Policy
  • 5.4 Planning
  • 6.2.1 Management direction for information security
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • SPS220-20 Risk Management Strategy
  • SPS220-28 Annual Board Risk Management Declaration
  • SPS220-42 Minimum Contents of the Risk Management Framework
  • SPS220-P22 Minimum Contents of the Risk Management Strategy

SASB Standards · 4 controls

  • SASB-3 Leadership and Governance (LG)
  • SASB-LG-2 Systemic Risk Management
  • SASB-LG-3 Critical Incident Risk Management
  • SASB-LG-5 Systemic Risk Management

SOC 2 · 4 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CPS220-05 Risk Management Strategy
  • CPS220-P21 Consistency of the Framework with the Business Plan
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

PCI DSS 4.0 · 3 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned

PCI P2PE · 3 controls

  • PCI-P2PE-16 Due diligence and onboarding
  • PCI-P2PE-18 Ongoing monitoring and assessment
  • PCI-P2PE-19 Concentration risk management

PCI PIN Security · 3 controls

  • PCI-PIN-16 Due diligence and onboarding
  • PCI-PIN-18 Ongoing monitoring and assessment
  • PCI-PIN-19 Concentration risk management

PCI SSF · 3 controls

  • PCI-SSF-03 Risk appetite and tolerance for IT risk
  • PCI-SSF-16 Due diligence and onboarding
  • PCI-SSF-17 Contractual security requirements
  • SOC-CY-DC1 Nature of Business and Operations
  • SOC-CY-DC3 Cybersecurity Risk Management Objectives
  • SOC-CY-DC4 Governance Structure
  • SOCI-S30AC Obligation to adopt a CIRMP
  • SOCI-S30AD Compliance with CIRMP
  • SOCI-S30AE Annual review of CIRMP

Solvency II · 3 controls

  • SII-P2-11 Remuneration Policy
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO 27001:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.4 Management responsibilities

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.4 Management responsibilities

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ADMF-1.5 Executive direction and risk appetite
  • ACQS-8-4 Risk Management
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

C5 (Germany) · 1 control

  • C5-OIS-01 Information Security Management System (ISMS)
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

DORA · 1 control

  • CJIS-19 Supply Chain Risk Management

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components
  • ID.RM-2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed
  • ID.RM-2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed

NIST SP 1800-32 · 1 control

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • TSSR-SEC-3 National Security Risk Management
  • CRM-3 Risk Management Framework
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 191 it maps to, and the evidence behind each claim, over MCP and REST.