Management, overseen by the board, sets up the structures, reporting lines and authority needed to pursue objectives. Points of focus: every structure is considered, including business units, legal entities, locations and outsourced providers; reporting lines are designed so authority can be exercised and information can flow; authority and responsibility are delegated with segregation of duties where needed; requirements for security, availability, confidentiality, privacy and processing integrity shape how roles are defined; and the need to interact with and oversee external parties is built into the structure. The 2022 revision adds, for privacy engagements, that legal and contractual privacy obligations shape how structures, reporting lines and authority are set up.
This control maps to 97 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
You are reading one control. How much of SOC 2 have you already done?
SOC 2 SOC2-CC1.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.