GV
— GOVERN
The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored
| Publié par | NIST |
|---|---|
| Version | 2.0 |
| Date de publication | 2024-02-26 |
| Langue | en |
| Exigences | 225 |
| Document source | csf.xlsx |
| Clé de plateforme | arcate:compliance:frameworks/nist-csf/2.0 |
GV
— GOVERN
The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored
GV.OC
— Organizational Context
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood
The organizational mission is understood and informs cybersecurity risk management
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Outcomes, capabilities, and services that the organization depends on are understood and communicated
GV.RM
— Risk Management Strategy
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
Risk management objectives are established and agreed to by organizational stakeholders
Risk appetite and risk tolerance statements are established, communicated, and maintained
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Strategic direction that describes appropriate risk response options is established and communicated
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
GV.RR
— Roles, Responsibilities, and Authorities
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
Cybersecurity is included in human resources practices
GV.PO
— Policy
Organizational cybersecurity policy is established, communicated, and enforced
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
GV.OV
— Oversight
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy