GV.OC – Organisational Context, Organisational Context addresses the organisation’s understanding of the circumstances surrounding its cyber security risk management decisions, covering the organisation’s mission, stakeholder expectations, dependencies, and legal, regulatory and contractual requirements., GV.RM – Risk Management Strategy, This Category is focused on ensuring the organisation has established and communicated its priorities, constraints, risk tolerance and appetite statements, and assumptions, and is using these elements to support operational risk decisions., GV.RR – Roles, Responsibilities and Authorities, This includes leadership’s responsibility for managing cyber security risk, providing resources needed in accordance with cyber security risk strategy, roles, responsibilities and policies, and fostering a culture of risk awareness, ethical conduct, and ongoing improvement., GV.PO – Policy, This Category requires the organisation to establish a cyber security policy that is communicated to personnel across the organisation, and enforced., GV.OV – Oversight, The organisation will need to assess the results of their cyber security risk performance and activities, and use this information to improve their cyber security risk strategy according to the risks and needs of your organisation., GV.SC – Cybersecurity Supply Chain Risk Management, Cybersecurity Supply Chain Risk Management focuses on identifying, establishing, managing, monitoring and improving your cyber security supply chain risk management and improvement processes.

NISTs Cybersecurity Framework's Govern Function

Rangliste

Visuel stil

Indstillinger

Skift skabelon

Gendan automatisk gemt: ?