Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-GV.RR-04 NIST Cybersecurity Framework 2.0
GV - Govern
NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-04: Cybersecurity is included in human resources practices Cybersecurity is included in human resources practices. Control from NIST Cybersecurity Framework 2.0 framework, domain: GV - Govern.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 101 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.11 Return of assets 6.1 Screening 6.2 Terms and conditions of employment 6.3 Information security awareness, education and training 6.4 Disciplinary process 6.5 Responsibilities after termination or change of employment 6.6 Confidentiality or non-disclosure agreements C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets C5-HR-01 Verification of qualification and trustworthiness C5-HR-02 Employment terms and conditions C5-HR-04 Disciplinary measures C5-HR-05 Responsibilities in the event of termination or change of employment C5-HR-06 Confidentiality agreements 5.11 Return of assets 6.1 Screening 6.2 Terms and conditions of employment 6.4 Disciplinary process 6.5 Responsibilities after termination or change of employment 6.6 Confidentiality or non-disclosure agreements PS-1 Policy and Procedures PS-2 Position Risk Designation PS-3 Personnel Screening PS-4 Personnel Termination PS-5 Personnel Transfer PS-1 Policy and Procedures PS-2 Position Risk Designation PS-3 Personnel Screening PS-4 Personnel Termination PS-5 Personnel Transfer 6.4 Human resource security 6.4.1 Prior to employment 6.4.2 During employment 6.4.3 Termination and change of employment 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access 8.2.5 8.2.5 Terminated users' access revoked immediately 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4) SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5) SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties ISM-0430 Same-day removal of access ISM-0434 Screening and clearances before access ISM-2003 Awareness of cyber workforce and skills gaps CIS-14.1 Establish and Maintain a Security Awareness Program CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process CPS234-P30 Independence and Skill of Testing Personnel CPS234-P33 Skill of Personnel Providing Control Assurance Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis Art.21.2.i Human resources security, access control policies and asset management 3.9.1e Enhanced Personnel Screening 3.9.2e Insider Threat Program ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ASD37-37 Personnel management (Very Good) AUCDR-IS-6 Information security training and awareness program ITSG33-PS Personnel Security (PS) PR.IP-11 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening) PR.IP-11 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in GV - Govern NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.