Risk management objectives are established and agreed to by organizational stakeholders
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
| Citation | GV.RM |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/GV.RM |
| Emplacement dans la source | row 10 of sheet 'CSF 2.0' |
| Publié par | NIST |
Exigences filles
Risk appetite and risk tolerance statements are established, communicated, and maintained
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Strategic direction that describes appropriate risk response options is established and communicated
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions