NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-01: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 61 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

ISO 27701:2019 · 5 controls

  • 5.3 Leadership
  • 5.3.1 Leadership and commitment
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 6.2.1 Management direction for information security
  • 6.3.1 Internal organization

ISO/IEC 42001:2023 · 4 controls

  • 4.4 AI management system
  • 5.1 Leadership and commitment
  • 9.3 Management review
  • A.3 Internal organization
  • CPS220-02 Board Responsibility for the Risk Management Framework
  • CPS220-20 Annual Board Risk Management Declaration
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • BMA-12 Board and Senior Management Oversight
  • BMA-4 Chief Information Security Officer
  • BMA-5 Three Lines of Defence

SOC 2 · 3 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities

APRA CPS 234 · 2 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • ADMF-1.1 Establish data management governance functions
  • ADMF-2.1 Leadership commitment in policy (who)
  • ISM-0714 Appointment of a CISO
  • ISM-2001 Championing a positive cyber security culture

C5 (Germany) · 2 controls

  • C5-BCM-01 Top management responsibility
  • C5-OIS-01 Information Security Management System (ISMS)

ISO 27001:2022 · 2 controls

  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities
  • SEC-CYB-08 Board Oversight of Cybersecurity Risks
  • SECCYB-3 Governance (Item 106(c)) - Board and Management Oversight
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known
  • SPS220-13 Board Responsibility for the Risk Management Framework
  • ASIC-CR-GOV-1 Board engagement and periodic review of cyber strategy
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities
  • BE-CF-35 Cybersecurity governance and policy

C2M2 · 1 control

  • WORKFORCE-1 Establish Cybersecurity Responsibilities and Workforce
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

DORA · 1 control

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 5.1 Leadership and commitment

ISO 27002:2022 · 1 control

  • 5.4 Management responsibilities

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • 161R1-PM-2 Information Security Program Leadership Role

NIST SP 800-181 · 1 control

NIST SP 800-218 · 1 control

  • GV.RR-01 GV.RR-01 Leadership accountable for cybersecurity risk, including incident response

PCI DSS 4.0 · 1 control

  • 12.1.4 12.1.4 Executive ownership of information security formally assigned

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.