NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-05: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 42 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

  • CPS220-16 Management Information System and Data Framework
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS220-P40 Chief Risk Officer Reporting Lines and Board Access

ISO 27001:2022 · 4 controls

  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation 
  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility

ISO 27701:2019 · 3 controls

  • 5.5.4 Communication
  • 6.3.1 Internal organization
  • 6.9.1 Operational procedures and responsibilities

ISO/IEC 42001:2023 · 3 controls

  • 7.4 Communication
  • A.3 Internal organization
  • A.8 Information for interested parties of AI systems

SOC 2 · 3 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • ISM-0718 CISO reporting to the board
  • ISM-0720 Cyber security communications strategy

CIS Controls v8 · 2 controls

  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response

ISO 22301:2019 · 2 controls

  • 7.4 Communication
  • 8.4.3 Warning and communication

ISO 27002:2022 · 2 controls

  • 5.5 Contact with authorities
  • 5.6 Contact with special interest groups
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known
  • CPS230-P23 Senior Management Information to the Board on Resilience Decisions

APRA CPS 234 · 1 control

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

NIS2 Directive · 1 control

  • ID.SC-1 ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.