NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 111 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 11.1.2 11.1.2 Roles for security testing assigned and understood
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 4.1.2 4.1.2 Requirement 4 roles and responsibilities assigned
  • 5.1.2 5.1.2 Requirement 5 roles and responsibilities assigned
  • 6.1.2 6.1.2 Requirement 6 roles and responsibilities assigned
  • 7.1.2 7.1.2 Requirement 7 roles and responsibilities assigned
  • 9.1.2 9.1.2 Requirement 9 roles and responsibilities assigned
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 3.1.2 3.1.2 Assigned duties for Requirement 3 activities
  • 8.1.2 8.1.2 Requirement 8 roles and responsibilities assigned

NIST SP 800-53 Rev 5 · 11 controls

ISO 27701:2019 · 8 controls

  • 5.3 Leadership
  • 5.3.3 Organizational roles, responsibilities and authorities
  • 6.2.1 Management direction for information security
  • 6.3 Organization of information security
  • 6.3.1 Internal organization
  • 6.4 Human resource security
  • 6.5.1 Responsibility for assets
  • 6.9.1 Operational procedures and responsibilities

CIS Controls v8 · 6 controls

  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-17.1 Designate Personnel to Manage Incident Handling
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.5 Assign Key Roles and Responsibilities
  • CIS-6.1 Establish an Access Granting Process

ISO/IEC 42001:2023 · 5 controls

  • 5.3 Roles, responsibilities and authorities
  • A.3 Internal organization
  • A.3.2 AI roles and responsibilities
  • A.4.6 Human resources
  • A.9.2 Processes for responsible use of AI systems
  • CPS220-09 Designation of a Chief Risk Officer
  • CPS220-10 Designated Risk Management Function
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P39 Independence of the Chief Risk Officer
  • ADMF-1.1 Establish data management governance functions
  • ADMF-1.2 Data management function responsibilities
  • ADMF-1.3 Business process function responsibilities

HIPAA Security Rule · 3 controls

ISO 22301:2019 · 3 controls

  • 4.4 Business continuity management system
  • 5.3 Roles, responsibilities and authorities
  • 8.4.1 General

ISO 27001:2022 · 3 controls

  • 5.2 Information security roles and responsibilities
  • 5.24 Information security incident management planning and preparation 
  • 5.3 Segregation of duties

ISO 27002:2022 · 3 controls

  • 5.2 Information security roles and responsibilities
  • 5.3 Segregation of duties
  • 5.4 Management responsibilities
  • DE.DP-1 DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability
  • ID.AM-6 ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
  • ID.GV-2 ID.GV-2: Information security roles & responsibilities are coordinated and aligned with internal roles and external partners
  • DE.DP-1 DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability
  • ID.AM-6 ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
  • ID.GV-2 ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners

NIST SP 800-181 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-P19 Policy Direction to All Responsible Parties
  • SEC10-BP01 Identify key personnel and external resources
  • SEC11-BP08 Build a program that embeds security ownership in workload teams
  • ISM-1071 Designated system owners
  • ISM-1997 Defining cyber security roles and responsibilities

C5 (Germany) · 2 controls

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • PL-1 Policy and Procedures
  • PS-9 Position Descriptions (PS-9)

FedRAMP Moderate · 2 controls

  • PL-1 Policy and Procedures
  • PS-9 Position Descriptions (PS-9)

NIST SP 800-66 Rev 2 · 2 controls

  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • SPS220-16 Designated Risk Management Function
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities

BCBS 239 · 1 control

  • BCBS239-P1 Governance
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-218 · 1 control

  • GV.RR-02 GV.RR-02 Incident response roles documented in policy and given the authority they need
  • SEC-CYB-09 Management Role and Expertise in Cybersecurity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.