NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-06: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 41 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

  • CPS220-02 Board Responsibility for the Risk Management Framework
  • CPS220-P28 Minimum Contents of the Risk Appetite Statement
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

FedRAMP High · 3 controls

  • RA-2 Security Categorization
  • RA-3 Risk Assessment
  • RA-7 Risk Response

HIPAA Security Rule · 3 controls

ISO/IEC 42001:2023 · 3 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment

NIST SP 800-66 Rev 2 · 3 controls

CIS Controls v8 · 2 controls

  • CIS-15.3 Classify Service Providers
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities

FedRAMP Moderate · 2 controls

  • RA-2 Security Categorization
  • RA-3 Risk Assessment

ISO 22301:2019 · 2 controls

  • 6.1 Actions to address risks and opportunities
  • 8.2.3 Risk assessment
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model
  • ISM-1203 Threat and risk assessment for each system

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

ISO 27701:2019 · 1 control

  • 5.6.2 Information security risk assessment

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security
  • ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
  • ID.RM-1 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document
  • GV.RM-06 GV.RM-06 A standard risk method used to prioritize incidents and set escalation criteria

PCI DSS 4.0 · 1 control

  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement

SOC 2 · 1 control

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RM-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.