The organizational mission is understood and informs cybersecurity risk management
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood
| Citation | GV.OC |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/GV.OC |
| Emplacement dans la source | row 4 of sheet 'CSF 2.0' |
| Publié par | NIST |
Exigences filles
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Outcomes, capabilities, and services that the organization depends on are understood and communicated