Skip to content

GOVERN (GV)

The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored

Informative References

  • CRI Profile v2.0: GV
  • CSF v1.1: ID.GV
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.2
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • SCF: GOV-01
  • SCF: GOV-05
  • SCF: RSK-01
  • SP 800-221A: GV.PO

Organizational Context (GV.OC)

The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood

Informative References

  • CRI Profile v2.0: GV.OC
  • CSF v1.1: ID.BE
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(a)
  • ISO/IEC 27001:2022: Mandatory Clause: 4.4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.2
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • SCF: CPL-01
  • SCF: TPM-05.4
  • SP 800-221A: GV.CT
  • SP 800-221A: GV.CT-5
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition

GV.OC-01

The organizational mission is understood and informs cybersecurity risk management

Implementation Examples

  • Ex1: Share the organization's mission (e.g., through vision and mission statements, marketing, and service strategies) to provide a basis for identifying risks that may impede that mission

Informative References

  • BXAIOS: Chapter 2 - Unify the Vision
  • CCMv4.0: BCR-01
  • CCMv4.0: BCR-07
  • CRI Profile v2.0: GV.OC-01
  • CRI Profile v2.0: GV.OC-01.01
  • CSF v1.1: ID.BE-2
  • CSF v1.1: ID.BE-3
  • CoP: A3
  • IRP: IRP-Sec-1
  • ISO/IEC 27001:2022: Mandatory Clause: 4.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1,
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.2
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Annex A Controls:
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM09-2025
  • PCI DSS: 12.1.1
  • SCF: RSK-01.1
  • SCF: TDA-06.2
  • SP 800-221A: GV.CT-5
  • SP 800-221A: GV.CT-3
  • SP 800-53 Rev 5.1.1: PM-11
  • SP 800-53 Rev 5.2.0: PM-11
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus

GV.OC-02

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

Implementation Examples

  • Ex1: Identify relevant internal stakeholders and their cybersecurity-related expectations (e.g., performance and risk expectations of officers, directors, and advisors; cultural expectations of employees)
  • Ex2: Identify relevant external stakeholders and their cybersecurity-related expectations (e.g., privacy expectations of customers, business expectations of partnerships, compliance expectations of regulators, ethics expectations of society)

Informative References

  • CCMv4.0: STA-08
  • CCMv4.0: STA-13
  • CRI Profile v2.0: GV.OC-02
  • CRI Profile v2.0: GV.OC-02.01
  • CRI Profile v2.0: GV.OC-02.02
  • CRI Profile v2.0: GV.OC-02.03
  • CSF v1.1: ID.SC-2
  • CSF v1.1: ID.GV-2
  • CoP: A1
  • CoP: E2
  • CoP: E3
  • ISO/IEC 27001:2022: Mandatory Clause: 4.1
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2
  • ISO/IEC 27001:2022: Mandatory Clause: 4.4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.2
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Annex A Controls:
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM09-2025
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.5
  • PCI DSS: 12.9.1
  • PCI DSS: 12.9.2
  • PCI DSS: 12.1.4
  • SCF: TPM-05
  • SCF: TPM-05.4
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.OV-2
  • SP 800-221A: GV.CT-2
  • SP 800-221A: GV.CT-3
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.1.1: SR-08
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-05
  • SP 800-53 Rev 5.2.0: SR-06
  • SP 800-53 Rev 5.2.0: SR-08
  • SP-800-37 Rev 2: RMF Prepare Step - Organization and Mission/Business Level - Task P-1: Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step - Organization and Mission/Business Level - Task P-3: Risk Assessment - Organizat
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition
  • SSDF: PO.2.1

GV.OC-03

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

Implementation Examples

  • Ex1: Determine a process to track and manage legal and regulatory requirements regarding protection of individuals' information (e.g., Health Insurance Portability and Accountability Act, California Consumer Privacy Act, General Data Protection Regulation)
  • Ex2: Determine a process to track and manage contractual requirements for cybersecurity management of supplier, customer, and partner information
  • Ex3: Align the organization's cybersecurity strategy with legal, regulatory, and contractual requirements

Informative References

  • CCMv4.0: CEK-12
  • CCMv4.0: CEK-13
  • CCMv4.0: CEK-14
  • CCMv4.0: CEK-15
  • CCMv4.0: CEK-16
  • CCMv4.0: CEK-17
  • CCMv4.0: CEK-18
  • CCMv4.0: CEK-19
  • CCMv4.0: CEK-20
  • CCMv4.0: CEK-21
  • CCMv4.0: DSP-01
  • CCMv4.0: DSP-10
  • CCMv4.0: DSP-11
  • CCMv4.0: DSP-12
  • CCMv4.0: DSP-16
  • CCMv4.0: DSP-18
  • CCMv4.0: GRC-07
  • CCMv4.0: HRS-13
  • CCMv4.0: STA-05
  • CCMv4.0: STA-13
  • CRI Profile v2.0: GV.OC-03
  • CRI Profile v2.0: GV.OC-03.01
  • CRI Profile v2.0: GV.OC-03.02
  • CSF v1.1: ID.GV-3
  • CoP: A1
  • CoP: D3
  • CoP: E2
  • CoP: E3
  • CoP: E4
  • CoP: E5
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(a)
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM09-2025
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.4
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.1
  • PCI DSS: 12.9.1
  • PCI DSS: 12.9.2
  • PCI DSS: 3.2.1
  • PCI DSS: 9.4.6
  • PCI DSS: 9.4.7
  • SCF: CPL-01
  • SCF: CPL-02
  • SCF: PRI-01
  • SCF: TPM-05
  • SCF: TPM-05.2
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-03
  • SDOS: SDOS-GV-05
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AT-01
  • SP 800-53 Rev 5.1.1: AU-01
  • SP 800-53 Rev 5.1.1: CA-01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.1.1: MA-01
  • SP 800-53 Rev 5.1.1: MP-01
  • SP 800-53 Rev 5.1.1: PE-01
  • SP 800-53 Rev 5.1.1: PL-01
  • SP 800-53 Rev 5.1.1: PM-01
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PT-01
  • SP 800-53 Rev 5.1.1: RA-01
  • SP 800-53 Rev 5.1.1: SA-01
  • SP 800-53 Rev 5.1.1: SC-01
  • SP 800-53 Rev 5.1.1: SI-01
  • SP 800-53 Rev 5.1.1: SR-01
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PT
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AT-01
  • SP 800-53 Rev 5.2.0: AU-01
  • SP 800-53 Rev 5.2.0: CA-01
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP 800-53 Rev 5.2.0: MA-01
  • SP 800-53 Rev 5.2.0: MP-01
  • SP 800-53 Rev 5.2.0: PE-01
  • SP 800-53 Rev 5.2.0: PL-01
  • SP 800-53 Rev 5.2.0: PM-01
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PT-01
  • SP 800-53 Rev 5.2.0: RA-01
  • SP 800-53 Rev 5.2.0: SA-01
  • SP 800-53 Rev 5.2.0: SC-01
  • SP 800-53 Rev 5.2.0: SI-01
  • SP 800-53 Rev 5.2.0: SR-01
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PT
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-17 Requirements Allocation
  • SSDF: PO.1.1
  • SSDF: PO.1.2

GV.OC-04

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Implementation Examples

  • Ex1: Establish criteria for determining the criticality of capabilities and services as viewed by internal and external stakeholders
  • Ex2: Determine (e.g., from a business impact analysis) assets and business operations that are vital to achieving mission objectives and the potential impact of a loss (or partial loss) of such operations
  • Ex3: Establish and communicate resilience objectives (e.g., recovery time objectives) for delivering critical capabilities and services in various operating states (e.g., under attack, during recovery, normal operation)

Informative References

  • CCMv4.0: BCR-01
  • CCMv4.0: BCR-02
  • CCMv4.0: BCR-03
  • CCMv4.0: BCR-11
  • CCMv4.0: IVS-02
  • CCMv4.0: STA-05
  • CRI Profile v2.0: GV.OC-04
  • CRI Profile v2.0: GV.OC-04.01
  • CRI Profile v2.0: GV.OC-04.02
  • CRI Profile v2.0: GV.OC-04.03
  • CRI Profile v2.0: GV.OC-04.04
  • CSF v1.1: ID.BE-4
  • CSF v1.1: ID.BE-5
  • CoP: A1
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(a)
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM09-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.5.2
  • PCI DSS: 12.5.1
  • SCF: BCD-02
  • SCF: TPM-02
  • SP 800-221A: MA.RI-1
  • SP 800-53 Rev 5.1.1: PM-08
  • SP 800-53 Rev 5.1.1: PM-11
  • SP 800-53 Rev 5.1.1: CP-02(08)
  • SP 800-53 Rev 5.1.1: PM-30(01)
  • SP 800-53 Rev 5.1.1: RA-09
  • SP 800-53 Rev 5.2.0: PM-08
  • SP 800-53 Rev 5.2.0: PM-11
  • SP 800-53 Rev 5.2.0: CP-02(08)
  • SP 800-53 Rev 5.2.0: PM-30(01)
  • SP 800-53 Rev 5.2.0: RA-09
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders

GV.OC-05

Outcomes, capabilities, and services that the organization depends on are understood and communicated

Implementation Examples

  • Ex1: Create an inventory of the organization's dependencies on external resources (e.g., facilities, cloud-based hosting providers) and their relationships to organizational assets and business functions
  • Ex2: Identify and document external dependencies that are potential points of failure for the organization's critical capabilities and services, and share that information with appropriate personnel

Informative References

  • CCMv4.0: BCR-11
  • CCMv4.0: STA-01
  • CCMv4.0: STA-04
  • CRI Profile v2.0: GV.OC-05
  • CRI Profile v2.0: GV.OC-05.01
  • CRI Profile v2.0: GV.OC-05.02
  • CRI Profile v2.0: GV.OC-05.03
  • CRI Profile v2.0: GV.OC-05.04
  • CSF v1.1: ID.BE-1
  • CSF v1.1: ID.BE-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Control 5.8
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.4
  • PCI DSS: 12.9.1
  • PCI DSS: 12.9.2
  • PCI DSS: 1.2.3
  • PCI DSS: 1.2.4
  • PCI DSS: 12.5.2
  • PCI DSS: 12.5.1
  • SCF: BCD-02
  • SCF: TPM-02
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-221A: GV.CT-5
  • SP 800-221A: MA.RI-1
  • SP 800-53 Rev 5.1.1: PM-11
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.2.0: PM-11
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-05
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification

Risk Management Strategy (GV.RM)

The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions

Informative References

  • CRI Profile v2.0: GV.RM
  • CSF v1.1: ID.RM
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-006
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-011
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • SCF: GOV-04
  • SCF: PRM-01
  • SCF: RSK-01
  • SCF: RSK-01.1
  • SP 800-221A: GV.BE-3
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.RM-01

Risk management objectives are established and agreed to by organizational stakeholders

Implementation Examples

  • Ex1: Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur
  • Ex2: Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control systems)
  • Ex3: Senior leaders agree about cybersecurity objectives and use them for measuring and managing risk and performance

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: CEK-07
  • CRI Profile v2.0: GV.RM-01
  • CRI Profile v2.0: GV.RM-01.01
  • CRI Profile v2.0: GV.RM-01.02
  • CRI Profile v2.0: GV.RM-01.03
  • CRI Profile v2.0: GV.RM-01.04
  • CRI Profile v2.0: GV.RM-01.05
  • CSF v1.1: ID.RM-1
  • CoP: A1
  • IRP: IRP-Sec-2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-011
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • PCI DSS: 12.1.4
  • PCI DSS: 12.1.2
  • PCI DSS: 12.1.1
  • SCF: GOV-01
  • SCF: RSK-01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SR-02
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.RM-02

Risk appetite and risk tolerance statements are established, communicated, and maintained

Implementation Examples

  • Ex1: Determine and communicate risk appetite statements that convey expectations about the appropriate level of risk for the organization
  • Ex2: Translate risk appetite statements into specific, measurable, and broadly understandable risk tolerance statements
  • Ex3: Refine organizational objectives and risk appetite periodically based on known risk exposure and residual risk

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: BCR-03
  • CCMv4.0: IVS-08
  • CRI Profile v2.0: GV.RM-02
  • CRI Profile v2.0: GV.RM-02.01
  • CRI Profile v2.0: GV.RM-02.02
  • CRI Profile v2.0: GV.RM-02.03
  • CSF v1.1: ID.RM-2
  • CSF v1.1: ID.RM-3
  • CoP: A3
  • Guardian-SDK: GS-CF-01
  • IRP: IRP-Sec-5
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: DD-WRL-006
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-011
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM09-2025
  • SDOS: SDOS-RM-01
  • SDOS: SDOS-RM-02
  • SDOS: SDOS-RM-03
  • SP 800-221A: GV.BE-1
  • SP 800-221A: GV.BE-3
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.2.0: PM-09
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.RM-03

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Implementation Examples

  • Ex1: Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety)
  • Ex2: Include cybersecurity risk managers in enterprise risk management planning
  • Ex3: Establish criteria for escalating cybersecurity risks within enterprise risk management

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: A&A-03
  • CRI Profile v2.0: GV.RM-03
  • CRI Profile v2.0: GV.RM-03.01
  • CRI Profile v2.0: GV.RM-03.02
  • CRI Profile v2.0: GV.RM-03.03
  • CRI Profile v2.0: GV.RM-03.04
  • CSF v1.1: ID.GV-4
  • CoP: A2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: DD-WRL-002
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-011
  • NICE Framework: OG-WRL-015
  • PCI DSS: 12.5.3
  • PCI DSS: 10.4.2.1
  • PCI DSS: 11.3.1.1
  • PCI DSS: 11.6.1
  • PCI DSS: 12.10.4.1
  • PCI DSS: 5.2.3.1
  • PCI DSS: 5.3.2.1
  • PCI DSS: 7.2.5.1
  • PCI DSS: 8.6.3
  • PCI DSS: 6.3.1
  • PCI DSS: 6.3.3
  • PCI DSS: 9.5.1.2.1
  • PCI DSS: 12.3.4
  • PCI DSS: 12.3.3
  • PCI DSS: 12.8.3
  • SCF: GOV-01
  • SCF: RSK-01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-221A: GV.PO-2
  • SP 800-221A: GV.PO-3
  • SP 800-53 Rev 5.1.1: PM-03
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.2.0: PM-03
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SA-24
  • SP 800-53 Rev 5.2.0: SR-02
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.RM-04

Strategic direction that describes appropriate risk response options is established and communicated

Implementation Examples

  • Ex1: Specify criteria for accepting and avoiding cybersecurity risk for various classifications of data
  • Ex2: Determine whether to purchase cybersecurity insurance
  • Ex3: Document conditions under which shared responsibility models are acceptable (e.g., outsourcing certain cybersecurity functions, having a third party perform financial transactions on behalf of the organization, using public cloud-based services)

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: BCR-03
  • CCMv4.0: STA-01
  • CRI Profile v2.0: GV.RM-04
  • CRI Profile v2.0: GV.RM-04.01
  • CSF v1.1: ID.RM-2
  • CoP: B1
  • CoP: B2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-015
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.6
  • SCF: RSK-01
  • SCF: RSK-01.1
  • SCF: RSK-06.1
  • SDOS: SDOS-GV-02
  • SDOS: SDOS-RM-01
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-221A: GV.BE-1
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: SR-02
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O

GV.RM-05

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Implementation Examples

  • Ex1: Determine how to update senior executives, directors, and management on the organization's cybersecurity posture at agreed-upon intervals
  • Ex2: Identify how all departments across the organization - such as management, operations, internal auditors, legal, acquisition, physical security, and HR - will communicate with each other about cybersecurity risks

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: STA-01
  • CCMv4.0: STA-08
  • CRI Profile v2.0: GV.RM-05
  • CRI Profile v2.0: GV.RM-05.01
  • CRI Profile v2.0: GV.RM-05.02
  • CSF v1.1: ID.SC-1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • NICE Framework: DD-WRL-006
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-008
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.5
  • PCI DSS: 12.9.2
  • PCI DSS: 12.9.1
  • PCI DSS: 12.8.4
  • PCI DSS: 12.5.3
  • PCI DSS: 12.10.1
  • PCI DSS: 10.7.1
  • PCI DSS: 10.7.2
  • SCF: GOV-04
  • SCF: HRS-03
  • SCF: TPM-05.4
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-30
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders

GV.RM-06

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

Implementation Examples

  • Ex1: Establish criteria for using a quantitative approach to cybersecurity risk analysis, and specify probability and exposure formulas
  • Ex2: Create and use templates (e.g., a risk register) to document cybersecurity risk information (e.g., risk description, exposure, treatment, and ownership)
  • Ex3: Establish criteria for risk prioritization at the appropriate levels within the enterprise
  • Ex4: Use a consistent list of risk categories to support integrating, aggregating, and comparing cybersecurity risks

Informative References

  • CCMv4.0: GRC-02
  • CCMv4.0: TVM-08
  • CCMv4.0: IVS-08
  • CRI Profile v2.0: GV.RM-06
  • CRI Profile v2.0: GV.RM-06.01
  • CSF v1.1: ID.RM-1
  • IRP: IRP-Sec-2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • NICE Framework: DD-WRL-006
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-006
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: OG-WRL-015
  • PCI DSS: 12.3.1
  • PCI DSS: 12.3.2
  • PCI DSS: 10.4.2.1
  • PCI DSS: 11.3.1.1
  • PCI DSS: 11.6.1
  • PCI DSS: 12.10.4.1
  • PCI DSS: 5.2.3.1
  • PCI DSS: 5.3.2.1
  • PCI DSS: 7.2.5.1
  • PCI DSS: 8.6.3
  • PCI DSS: 6.3.1
  • PCI DSS: 6.3.3
  • PCI DSS: 9.5.1.2.1
  • PCI DSS: 12.3.4
  • PCI DSS: 12.3.3
  • PCI DSS: 12.8.3
  • SCF: RSK-01
  • SCF: RSK-01.1
  • SCF: RSK-04
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RM-01
  • SDOS: SDOS-RM-02
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: RA-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O

GV.RM-07

Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

Implementation Examples

  • Ex1: Define and communicate guidance and methods for identifying opportunities and including them in risk discussions (e.g., strengths, weaknesses, opportunities, and threats [SWOT] analysis)
  • Ex2: Identify stretch goals and document them
  • Ex3: Calculate, document, and prioritize positive risks alongside negative risks

Informative References

  • CCMv4.0: GRC-02
  • CRI Profile v2.0: GV.RM-07
  • CRI Profile v2.0: GV.RM-07.01
  • ISO/IEC 27001:2022: Mandatory Clause: 6.11
  • ISO/IEC 27001:2022: Annex A Controls: None
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-015
  • SCF: RSK-01.1
  • SDOS: SDOS-GV-02
  • SDOS: SDOS-RM-01
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: RA-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

Roles, Responsibilities, and Authorities (GV.RR)

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated

Informative References

  • CRI Profile v2.0: GV.RR
  • CSF v1.1: ID.GV-2
  • ISO/IEC 27001:2022: Mandatory Clause: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.4
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • SCF: HRS-03
  • SCF: TPM-05.4
  • SP 800-221A: GV.OV-2
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders
  • SSDF: PO.2.1

GV.RR-01

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Implementation Examples

  • Ex1: Leaders (e.g., directors) agree on their roles and responsibilities in developing, implementing, and assessing the organization's cybersecurity strategy
  • Ex2: Share leaders' expectations regarding a secure and ethical culture, especially when current events present the opportunity to highlight positive or negative examples of cybersecurity risk management
  • Ex3: Leaders direct the CISO to maintain a comprehensive cybersecurity risk strategy and review and update it at least annually and after major events
  • Ex4: Conduct reviews to ensure adequate authority and coordination among those responsible for managing cybersecurity risk

Informative References

  • BXAIOS: Chapter 8 - Activate the Champions
  • CCMv4.0: HRS-09
  • CCMv4.0: HRS-13
  • CIS Controls v8.0: 14.1
  • CIS Controls v8.1: 14.1
  • CRI Profile v2.0: GV.RR-01
  • CRI Profile v2.0: GV.RR-01.01
  • CRI Profile v2.0: GV.RR-01.02
  • CRI Profile v2.0: GV.RR-01.03
  • CRI Profile v2.0: GV.RR-01.04
  • CRI Profile v2.0: GV.RR-01.05
  • CoP: A2
  • CoP: C1
  • CoP: E3
  • ISO/IEC 27001:2022: Mandatory Clause: 7.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.4
  • ISO/IEC 27001:2022: Control 5.4
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • PCI DSS: 12.1.4
  • PCI DSS: 12.6.1
  • PCI DSS: 6.2.2
  • PCI DSS: 12.10.6
  • PCI DSS: 12.1.3
  • SCF: GOV-01
  • SCF: GOV-04
  • SCF: RSK-01
  • SP 800-53 Rev 5.1.1: PM-02
  • SP 800-53 Rev 5.1.1: PM-19
  • SP 800-53 Rev 5.1.1: PM-23
  • SP 800-53 Rev 5.1.1: PM-24
  • SP 800-53 Rev 5.1.1: PM-29
  • SP 800-53 Rev 5.2.0: PM-02
  • SP 800-53 Rev 5.2.0: PM-19
  • SP 800-53 Rev 5.2.0: PM-23
  • SP 800-53 Rev 5.2.0: PM-24
  • SP 800-53 Rev 5.2.0: PM-29
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SSDF: PO.2.3

GV.RR-02

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Implementation Examples

  • Ex1: Document risk management roles and responsibilities in policy
  • Ex2: Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
  • Ex3: Include cybersecurity responsibilities and performance requirements in personnel descriptions
  • Ex4: Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement
  • Ex5: Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions

Informative References

  • CCMv4.0: CEK-02
  • CCMv4.0: GRC-06
  • CCMv4.0: HRS-02
  • CCMv4.0: HRS-03
  • CCMv4.0: HRS-06
  • CCMv4.0: HRS-08
  • CCMv4.0: HRS-09
  • CCMv4.0: HRS-13
  • CCMv4.0: SEF-08
  • CCMv4.0: STA-02
  • CCMv4.0: STA-04
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 14.9
  • CIS Controls v8.1: 14.9
  • CRI Profile v2.0: GV.RR-02
  • CRI Profile v2.0: GV.RR-02.01
  • CRI Profile v2.0: GV.RR-02.02
  • CRI Profile v2.0: GV.RR-02.03
  • CRI Profile v2.0: GV.RR-02.04
  • CRI Profile v2.0: GV.RR-02.05
  • CRI Profile v2.0: GV.RR-02.06
  • CRI Profile v2.0: GV.RR-02.07
  • CSF v1.1: ID.AM-6
  • CSF v1.1: ID.GV-2
  • CSF v1.1: DE.DP-1
  • CoP: B4
  • CoP: E1
  • CoP: E2
  • ISO/IEC 27001:2022: Mandatory Clause: 7.2
  • ISO/IEC 27001:2022: Annex A Controls: None
  • ISO/IEC 27001:2022: Control 5.2
  • ISO/IEC 27001:2022: Control 5.3
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 1.1.2
  • PCI DSS: 2.1.2
  • PCI DSS: 3.1.2
  • PCI DSS: 4.1.2
  • PCI DSS: 5.1.2
  • PCI DSS: 6.1.2
  • PCI DSS: 7.1.2
  • PCI DSS: 8.1.2
  • PCI DSS: 9.1.2
  • PCI DSS: 10.1.2
  • PCI DSS: 11.1.2
  • PCI DSS: 12.1.3
  • SCF: GOV-04
  • SCF: HRS-02
  • SCF: HRS-03
  • SCF: TPM-05.4
  • SDOS: SDOS-AD-01
  • SDOS: SDOS-EN-02
  • SDOS: SDOS-GV-01
  • SP 800-221A: GV.RR-1
  • SP 800-221A: GV.RR-2
  • SP 800-221A: GV.OV-2
  • SP 800-53 Rev 5.1.1: PM-02
  • SP 800-53 Rev 5.1.1: PM-13
  • SP 800-53 Rev 5.1.1: PM-19
  • SP 800-53 Rev 5.1.1: PM-23
  • SP 800-53 Rev 5.1.1: PM-24
  • SP 800-53 Rev 5.1.1: PM-29
  • SP 800-53 Rev 5.2.0: PM-02
  • SP 800-53 Rev 5.2.0: PM-13
  • SP 800-53 Rev 5.2.0: PM-19
  • SP 800-53 Rev 5.2.0: PM-23
  • SP 800-53 Rev 5.2.0: PM-24
  • SP 800-53 Rev 5.2.0: PM-29
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SSDF: PO.2.1

GV.RR-03

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

Implementation Examples

  • Ex1: Conduct periodic management reviews to ensure that those given cybersecurity risk management responsibilities have the necessary authority
  • Ex2: Identify resource allocation and investment in line with risk tolerance and response
  • Ex3: Provide adequate and sufficient people, process, and technical resources to support the cybersecurity strategy

Informative References

  • CRI Profile v2.0: GV.RR-03
  • CRI Profile v2.0: GV.RR-03.01
  • CRI Profile v2.0: GV.RR-03.02
  • CRI Profile v2.0: GV.RR-03.03
  • CSF v1.1: ID.RM-1
  • CoP: B3
  • IRP: IRP-Sec-4
  • ISO/IEC 27001:2022: Mandatory Clause: 7.1, 7.2
  • ISO/IEC 27001:2022: Annex A Controls:
  • ISO/IEC 27001:2022: Control 6.6
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • PCI DSS: 12.1.4
  • PCI DSS: 12.10.3
  • SCF: PRM-01
  • SCF: PRM-02
  • SCF: PRM-03
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: PM-03
  • SP 800-53 Rev 5.2.0: PM-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.RR-04

Cybersecurity is included in human resources practices

Implementation Examples

  • Ex1: Integrate cybersecurity risk management considerations into human resources processes (e.g., personnel screening, onboarding, change notification, offboarding)
  • Ex2: Consider cybersecurity knowledge to be a positive factor in hiring, training, and retention decisions
  • Ex3: Conduct background checks prior to onboarding new personnel for sensitive roles, and periodically repeat background checks for personnel with such roles
  • Ex4: Define and enforce obligations for personnel to be aware of, adhere to, and uphold security policies as they relate to their roles

Informative References

  • CCMv4.0: HRS-01
  • CCMv4.0: HRS-05
  • CCMv4.0: HRS-06
  • CCMv4.0: HRS-07
  • CCMv4.0: HRS-08
  • CCMv4.0: HRS-10
  • CCMv4.0: IAM-07
  • CIS Controls v8.0: 6.1
  • CIS Controls v8.0: 6.2
  • CIS Controls v8.1: 6.1
  • CIS Controls v8.1: 6.2
  • CRI Profile v2.0: GV.RR-04
  • CRI Profile v2.0: GV.RR-04.01
  • CRI Profile v2.0: GV.RR-04.02
  • CRI Profile v2.0: GV.RR-04.03
  • CSF v1.1: PR.IP-11
  • CoP: C1
  • ISO/IEC 27001:2022: Mandatory Clause: 7.3
  • ISO/IEC 27001:2022: Annex A Controls: 6.1
  • ISO/IEC 27001:2022: Annex A Controls: 6.2
  • ISO/IEC 27001:2022: Annex A Controls: 6.3
  • ISO/IEC 27001:2022: Annex A Controls: 6.4
  • ISO/IEC 27001:2022: Annex A Controls: 6.5
  • ISO/IEC 27001:2022: Annex A Controls: 6.6
  • ISO/IEC 27001:2022: Annex A Controls: 6.7
  • ISO/IEC 27001:2022: Annex A Controls: 6.8
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-010
  • PCI DSS: 12.7.1
  • PCI DSS: 12.6.3
  • PCI DSS: 7.2.2
  • PCI DSS: 8.2.5
  • PCI DSS: 9.3.1.1
  • SCF: HRS-01
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-53 Rev 5.1.1: PM-13
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PS-07
  • SP 800-53 Rev 5.1.1: PS-09
  • SP 800-53 Rev 5.2.0: PM-13
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PS-07
  • SP 800-53 Rev 5.2.0: PS-09
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

Policy (GV.PO)

Organizational cybersecurity policy is established, communicated, and enforced

Informative References

  • CRI Profile v2.0: GV.PO
  • CSF v1.1: ID.GV-1
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.36
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • SCF: GOV-02
  • SCF: HRS-07
  • SP 800-221A: GV.PO-1
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.PO-01

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Implementation Examples

  • Ex1: Create, disseminate, and maintain an understandable, usable risk management policy with statements of management intent, expectations, and direction
  • Ex2: Periodically review policy and supporting processes and procedures to ensure that they align with risk management strategy objectives and priorities, as well as the high-level direction of the cybersecurity policy
  • Ex3: Require approval from senior management on policy
  • Ex4: Communicate cybersecurity risk management policy and supporting processes and procedures across the organization
  • Ex5: Require personnel to acknowledge receipt of policy when first hired, annually, and whenever policy is updated

Informative References

  • BXAIOS: Chapter 3 - The Charter (POP Framework)
  • CCMv4.0: A&A-01
  • CCMv4.0: AIS-01
  • CCMv4.0: BCR-01
  • CCMv4.0: CCC-01
  • CCMv4.0: CEK-01
  • CCMv4.0: DCS-01
  • CCMv4.0: DCS-02
  • CCMv4.0: DCS-03
  • CCMv4.0: DCS-04
  • CCMv4.0: DSP-01
  • CCMv4.0: GRC-01
  • CCMv4.0: HRS-01
  • CCMv4.0: HRS-02
  • CCMv4.0: HRS-03
  • CCMv4.0: HRS-04
  • CCMv4.0: HRS-09
  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-02
  • CCMv4.0: IPY-01
  • CCMv4.0: IVS-01
  • CCMv4.0: LOG-01
  • CCMv4.0: SEF-01
  • CCMv4.0: SEF-02
  • CCMv4.0: STA-01
  • CCMv4.0: TVM-01
  • CCMv4.0: TVM-02
  • CCMv4.0: UEM-01
  • CCMv4.0: UEM-05
  • CRI Profile v2.0: GV.PO-01
  • CRI Profile v2.0: GV.PO-01.01
  • CRI Profile v2.0: GV.PO-01.02
  • CRI Profile v2.0: GV.PO-01.03
  • CRI Profile v2.0: GV.PO-01.04
  • CRI Profile v2.0: GV.PO-01.05
  • CRI Profile v2.0: GV.PO-01.06
  • CRI Profile v2.0: GV.PO-01.07
  • CRI Profile v2.0: GV.PO-01.08
  • CSF v1.1: ID.GV-1
  • CoP: C2
  • Guardian-SDK: GS-CF-01
  • IRP: IRP-Sec-5
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Control 5.1
  • ISO/IEC 27001:2022: Control 5.37
  • ISO/IEC 27001:2022: Control 6.1
  • ISO/IEC 27001:2022: Control 6.2
  • ISO/IEC 27001:2022: Control 6.4
  • ISO/IEC 27001:2022: Control 6.5
  • ISO/IEC 27001:2022: Control 6.7
  • ISO/IEC 27001:2022: Control 6.8
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 12.1.1
  • PCI DSS: 12.6.1
  • PCI DSS: 12.1.4
  • PCI DSS: 12.1.2
  • PCI DSS: 12.1.3
  • SCF: GOV-02
  • SCF: HRS-07
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-03
  • SDOS: SDOS-GV-04
  • SDOS: SDOS-GV-05
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AT-01
  • SP 800-53 Rev 5.1.1: AU-01
  • SP 800-53 Rev 5.1.1: CA-01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.1.1: MA-01
  • SP 800-53 Rev 5.1.1: MP-01
  • SP 800-53 Rev 5.1.1: PE-01
  • SP 800-53 Rev 5.1.1: PL-01
  • SP 800-53 Rev 5.1.1: PM-01
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PT-01
  • SP 800-53 Rev 5.1.1: RA-01
  • SP 800-53 Rev 5.1.1: SA-01
  • SP 800-53 Rev 5.1.1: SC-01
  • SP 800-53 Rev 5.1.1: SI-01
  • SP 800-53 Rev 5.1.1: SR-01
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AT-01
  • SP 800-53 Rev 5.2.0: AU-01
  • SP 800-53 Rev 5.2.0: CA-01
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP 800-53 Rev 5.2.0: MA-01
  • SP 800-53 Rev 5.2.0: MP-01
  • SP 800-53 Rev 5.2.0: PE-01
  • SP 800-53 Rev 5.2.0: PL-01
  • SP 800-53 Rev 5.2.0: PM-01
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PT-01
  • SP 800-53 Rev 5.2.0: RA-01
  • SP 800-53 Rev 5.2.0: SA-01
  • SP 800-53 Rev 5.2.0: SC-01
  • SP 800-53 Rev 5.2.0: SI-01
  • SP 800-53 Rev 5.2.0: SR-01
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.PO-02

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

Implementation Examples

  • Ex1: Update policy based on periodic reviews of cybersecurity risk management results to ensure that policy and supporting processes and procedures adequately maintain risk at an acceptable level
  • Ex2: Provide a timeline for reviewing changes to the organization's risk environment (e.g., changes in risk or in the organization's mission objectives), and communicate recommended policy updates
  • Ex3: Update policy to reflect changes in legal and regulatory requirements
  • Ex4: Update policy to reflect changes in technology (e.g., adoption of artificial intelligence) and changes to the business (e.g., acquisition of a new business, new contract requirements)

Informative References

  • CCMv4.0: A&A-01
  • CCMv4.0: AIS-01
  • CCMv4.0: BCR-01
  • CCMv4.0: CCC-01
  • CCMv4.0: CEK-01
  • CCMv4.0: DCS-01
  • CCMv4.0: DCS-02
  • CCMv4.0: DCS-03
  • CCMv4.0: DCS-04
  • CCMv4.0: DSP-01
  • CCMv4.0: GRC-01
  • CCMv4.0: GRC-03
  • CCMv4.0: HRS-01
  • CCMv4.0: HRS-02
  • CCMv4.0: HRS-03
  • CCMv4.0: HRS-04
  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-02
  • CCMv4.0: IPY-01
  • CCMv4.0: IVS-01
  • CCMv4.0: LOG-01
  • CCMv4.0: SEF-01
  • CCMv4.0: SEF-02
  • CCMv4.0: STA-01
  • CCMv4.0: TVM-01
  • CCMv4.0: TVM-02
  • CCMv4.0: UEM-01
  • CCMv4.0: UEM-05
  • CRI Profile v2.0: GV.PO-02
  • CRI Profile v2.0: GV.PO-02.01
  • CSF v1.1: ID.GV-1
  • CoP: C2
  • CoP: E1
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Control 5.31
  • ISO/IEC 27001:2022: Control 5.32
  • ISO/IEC 27001:2022: Control 5.34
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-010
  • PCI DSS: 12.1.2
  • PCI DSS: 1.1.1
  • PCI DSS: 2.1.1
  • PCI DSS: 3.1.1
  • PCI DSS: 4.1.1
  • PCI DSS: 5.1.1
  • PCI DSS: 6.1.1
  • PCI DSS: 7.1.1
  • PCI DSS: 8.1.1
  • PCI DSS: 9.1.1
  • PCI DSS: 10.1.1
  • PCI DSS: 11.1.1
  • SCF: GOV-03
  • SCF: HRS-07
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-04
  • SDOS: SDOS-GV-05
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AT-01
  • SP 800-53 Rev 5.1.1: AU-01
  • SP 800-53 Rev 5.1.1: CA-01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.1.1: MA-01
  • SP 800-53 Rev 5.1.1: MP-01
  • SP 800-53 Rev 5.1.1: PE-01
  • SP 800-53 Rev 5.1.1: PL-01
  • SP 800-53 Rev 5.1.1: PM-01
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PT-01
  • SP 800-53 Rev 5.1.1: RA-01
  • SP 800-53 Rev 5.1.1: SA-01
  • SP 800-53 Rev 5.1.1: SC-01
  • SP 800-53 Rev 5.1.1: SI-01
  • SP 800-53 Rev 5.1.1: SR-01
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AT-01
  • SP 800-53 Rev 5.2.0: AU-01
  • SP 800-53 Rev 5.2.0: CA-01
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP 800-53 Rev 5.2.0: MA-01
  • SP 800-53 Rev 5.2.0: MP-01
  • SP 800-53 Rev 5.2.0: PE-01
  • SP 800-53 Rev 5.2.0: PL-01
  • SP 800-53 Rev 5.2.0: PM-01
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PT-01
  • SP 800-53 Rev 5.2.0: RA-01
  • SP 800-53 Rev 5.2.0: SA-01
  • SP 800-53 Rev 5.2.0: SC-01
  • SP 800-53 Rev 5.2.0: SI-01
  • SP 800-53 Rev 5.2.0: SR-01
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

Oversight (GV.OV)

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy

Informative References

  • CRI Profile v2.0: GV.OV
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.2
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Mandatory Clause: 10.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-016
  • SCF: GOV-05
  • SCF: GOV-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
  • SP-800-37 Rev 2: RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System
  • SP-800-37 Rev 2: RMF Authorize Step: TASK R-3 Risk Response
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-2 Ongoing Assessments
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

GV.OV-01

Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

Implementation Examples

  • Ex1: Measure how well the risk management strategy and risk results have helped leaders make decisions and achieve organizational objectives
  • Ex2: Examine whether cybersecurity risk strategies that impede operations or innovation should be adjusted

Informative References

  • CRI Profile v2.0: GV.OV-01
  • CRI Profile v2.0: GV.OV-01.01
  • CRI Profile v2.0: GV.OV-01.02
  • CRI Profile v2.0: GV.OV-01.03
  • CoP: E1
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Control 5.5
  • ISO/IEC 27001:2022: Control 5.6
  • ISO/IEC 27001:2022: Control 5.24
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • NICE Framework: OG-WRL-016
  • PCI DSS: 12.3.1
  • PCI DSS: 12.10.6
  • PCI DSS: 12.10.2
  • PCI DSS: 12.4.2
  • PCI DSS: 12.4.2.1
  • PCI DSS: 10.7.1
  • PCI DSS: 10.7.2
  • SCF: GOV-05
  • SCF: GOV-03
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-221A: GV.AD-3
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AT-01
  • SP 800-53 Rev 5.1.1: AU-01
  • SP 800-53 Rev 5.1.1: CA-01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.1.1: MA-01
  • SP 800-53 Rev 5.1.1: MP-01
  • SP 800-53 Rev 5.1.1: PE-01
  • SP 800-53 Rev 5.1.1: PL-01
  • SP 800-53 Rev 5.1.1: PM-01
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PT-01
  • SP 800-53 Rev 5.1.1: RA-01
  • SP 800-53 Rev 5.1.1: SA-01
  • SP 800-53 Rev 5.1.1: SC-01
  • SP 800-53 Rev 5.1.1: SI-01
  • SP 800-53 Rev 5.1.1: SR-01
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: PM-31
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AT-01
  • SP 800-53 Rev 5.2.0: AU-01
  • SP 800-53 Rev 5.2.0: CA-01
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP 800-53 Rev 5.2.0: MA-01
  • SP 800-53 Rev 5.2.0: MP-01
  • SP 800-53 Rev 5.2.0: PE-01
  • SP 800-53 Rev 5.2.0: PL-01
  • SP 800-53 Rev 5.2.0: PM-01
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PT-01
  • SP 800-53 Rev 5.2.0: RA-01
  • SP 800-53 Rev 5.2.0: SA-01
  • SP 800-53 Rev 5.2.0: SC-01
  • SP 800-53 Rev 5.2.0: SI-01
  • SP 800-53 Rev 5.2.0: SR-01
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: PM-31
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
  • SP-800-37 Rev 2: RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System
  • SP-800-37 Rev 2: RMF Authorize Step: TASK R-3 Risk Response
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-2 Ongoing Assessments
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

GV.OV-02

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

Implementation Examples

  • Ex1: Review audit findings to confirm whether the existing cybersecurity strategy has ensured compliance with internal and external requirements
  • Ex2: Review the performance oversight of those in cybersecurity-related roles to determine whether policy changes are necessary
  • Ex3: Review strategy in light of cybersecurity incidents

Informative References

  • CRI Profile v2.0: GV.OV-02
  • CRI Profile v2.0: GV.OV-02.01
  • CRI Profile v2.0: GV.OV-02.02
  • CoP: E1
  • Guardian-SDK: GS-PO-02
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Control 5.27
  • ISO/IEC 27001:2022: Control 5.35
  • ISO/IEC 27001:2022: Control 5.36
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-007
  • PCI DSS: 12.10.6
  • PCI DSS: 12.10.2
  • PCI DSS: 12.4.2
  • PCI DSS: 12.4.2.1
  • PCI DSS: 12.5.3
  • PCI DSS: 12.8.4
  • PCI DSS: 10.7.1
  • PCI DSS: 10.7.2
  • PCI DSS: 11.4.4
  • PCI DSS: 12.3.4
  • PCI DSS: 12.5.2
  • SCF: GOV-03
  • SCF: RSK-01
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-221A: GV.AD-2
  • SP 800-221A: GV.AD-3
  • SP 800-221A: MA.RM-8
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-19
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: PM-31
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-19
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: PM-31
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.OV-03

Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

Implementation Examples

  • Ex1: Review key performance indicators (KPIs) to ensure that organization-wide policies and procedures achieve objectives
  • Ex2: Review key risk indicators (KRIs) to identify risks the organization faces, including likelihood and potential impact
  • Ex3: Collect and communicate metrics on cybersecurity risk management with senior leadership

Informative References

  • CCMv4.0: AIS-03
  • CRI Profile v2.0: GV.OV-03
  • CRI Profile v2.0: GV.OV-03.01
  • CRI Profile v2.0: GV.OV-03.02
  • CoP: E1
  • ISO/IEC 27001:2022: Mandatory Clause: 9.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Control 8.30
  • ISO/IEC 27001:2022: Control 8.32
  • ISO/IEC 27001:2022: Control 8.34
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-007
  • PCI DSS: 12.4.2
  • PCI DSS: 10.7.2
  • PCI DSS: 7.2.5.1
  • PCI DSS: 11.3.1
  • PCI DSS: 11.3.2
  • PCI DSS: 11.4.4
  • PCI DSS: 12.3.1
  • PCI DSS: 12.3.4
  • SCF: GOV-05
  • SCF: RSK-01
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-RS-01
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-221A: GV.OV-2
  • SP 800-221A: MA.RM-2
  • SP 800-53 Rev 5.1.1: PM-04
  • SP 800-53 Rev 5.1.1: PM-06
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: PM-04
  • SP 800-53 Rev 5.2.0: PM-06
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
  • SP-800-37 Rev 2: RMF Authorize Step: TASK R-3 Risk Response
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-2 Ongoing Assessments
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

Cybersecurity Supply Chain Risk Management (GV.SC)

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders

Informative References

  • CRI Profile v2.0: GV.SC
  • CSF v1.1: ID.SC
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-003
  • SCF: GOV-01
  • SCF: GOV-05
  • SCF: RSK-01
  • SCF: RSK-09
  • SCF: RSK-09.1
  • SCF: TPM-03
  • SP 800-221A: GV.OV-4
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy

GV.SC-01

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

Implementation Examples

  • Ex1: Establish a strategy that expresses the objectives of the cybersecurity supply chain risk management program
  • Ex2: Develop the cybersecurity supply chain risk management program, including a plan (with milestones), policies, and procedures that guide implementation and improvement of the program, and share the policies and procedures with the organizational stakeholders
  • Ex3: Develop and implement program processes based on the strategy, objectives, policies, and procedures that are agreed upon and performed by the organizational stakeholders
  • Ex4: Establish a cross-organizational mechanism that ensures alignment between functions that contribute to cybersecurity supply chain risk management, such as cybersecurity, IT, operations, legal, human resources, and engineering

Informative References

  • CCMv4.0: STA-01
  • CCMv4.0: STA-06
  • CCMv4.0: STA-08
  • CIS Controls v8.0: 15.2
  • CIS Controls v8.1: 15.2
  • CRI Profile v2.0: GV.SC-01
  • CRI Profile v2.0: GV.SC-01.01
  • CRI Profile v2.0: GV.SC-01.02
  • CSF v1.1: ID.SC-1
  • CoP: A4
  • IRP: IRP-Sec-1
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.21
  • ISO/IEC 27001:2022: Annex A Controls: 5.22
  • ISO/IEC 27001:2022: Control 5.19
  • ISO/IEC 27001:2022: Control 5.21
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.4
  • PCI DSS: 12.8.5
  • PCI DSS: 12.9.1
  • PCI DSS: 12.9.2
  • PCI DSS: 12.1.4
  • PCI DSS: 1.2.3
  • PCI DSS: 1.2.4
  • PCI DSS: 6.3.1
  • PCI DSS: 6.3.2
  • PCI DSS: 6.4.3
  • PCI DSS: 11.6.1
  • SCF: GOV-01
  • SCF: GOV-02
  • SCF: RSK-01
  • SCF: RSK-09
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders

GV.SC-02

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

Implementation Examples

  • Ex1: Identify one or more specific roles or positions that will be responsible and accountable for planning, resourcing, and executing cybersecurity supply chain risk management activities
  • Ex2: Document cybersecurity supply chain risk management roles and responsibilities in policy
  • Ex3: Create responsibility matrixes to document who will be responsible and accountable for cybersecurity supply chain risk management activities and how those teams and individuals will be consulted and informed
  • Ex4: Include cybersecurity supply chain risk management responsibilities and performance requirements in personnel descriptions to ensure clarity and improve accountability
  • Ex5: Document performance goals for personnel with cybersecurity risk management-specific responsibilities, and periodically measure them to demonstrate and improve performance
  • Ex6: Develop roles and responsibilities for suppliers, customers, and business partners to address shared responsibilities for applicable cybersecurity risks, and integrate them into organizational policies and applicable third-party agreements
  • Ex7: Internally communicate cybersecurity supply chain risk management roles and responsibilities for third parties
  • Ex8: Establish rules and protocols for information sharing and reporting processes between the organization and its suppliers

Informative References

  • CCMv4.0: HRS-09
  • CCMv4.0: HRS-10
  • CCMv4.0: HRS-13
  • CCMv4.0: IAM-11
  • CCMv4.0: STA-01
  • CCMv4.0: STA-02
  • CCMv4.0: STA-03
  • CCMv4.0: STA-04
  • CCMv4.0: STA-05
  • CCMv4.0: STA-06
  • CCMv4.0: STA-12
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 15.4
  • CIS Controls v8.1: 15.4
  • CRI Profile v2.0: GV.SC-02
  • CRI Profile v2.0: GV.SC-02.01
  • CSF v1.1: ID.AM-6
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.4
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.4
  • PCI DSS: 12.1.4
  • PCI DSS: 12.10.1
  • SCF: TPM-05
  • SCF: TPM-05.2
  • SCF: TPM-05.4
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.RR-1
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-05
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SSDF: PO.2.1

GV.SC-03

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

Implementation Examples

  • Ex1: Identify areas of alignment and overlap with cybersecurity and enterprise risk management
  • Ex2: Establish integrated control sets for cybersecurity risk management and cybersecurity supply chain risk management
  • Ex3: Integrate cybersecurity supply chain risk management into improvement processes
  • Ex4: Escalate material cybersecurity risks in supply chains to senior management, and address them at the enterprise risk management level

Informative References

  • CCMv4.0: STA-01
  • CCMv4.0: STA-06
  • CCMv4.0: STA-08
  • CCMv4.0: STA-11
  • CCMv4.0: STA-12
  • CCMv4.0: UEM-14
  • CRI Profile v2.0: GV.SC-03
  • CRI Profile v2.0: GV.SC-03.01
  • CSF v1.1: ID.SC-2
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.21
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 6.4.3
  • PCI DSS: 6.2.3
  • PCI DSS: 12.8.3
  • PCI DSS: 12.3.4
  • PCI DSS: 11.6.1
  • PCI DSS: 6.3.2
  • PCI DSS: 6.3.1
  • SCF: GOV-01
  • SCF: GOV-02
  • SCF: RSK-01
  • SCF: RSK-09
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.CT-2
  • SP 800-221A: GV.CT-3
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AT-01
  • SP 800-53 Rev 5.1.1: AU-01
  • SP 800-53 Rev 5.1.1: CA-01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.1.1: MA-01
  • SP 800-53 Rev 5.1.1: MP-01
  • SP 800-53 Rev 5.1.1: PE-01
  • SP 800-53 Rev 5.1.1: PL-01
  • SP 800-53 Rev 5.1.1: PM-01
  • SP 800-53 Rev 5.1.1: PS-01
  • SP 800-53 Rev 5.1.1: PT-01
  • SP 800-53 Rev 5.1.1: RA-01
  • SP 800-53 Rev 5.1.1: SA-01
  • SP 800-53 Rev 5.1.1: SC-01
  • SP 800-53 Rev 5.1.1: SI-01
  • SP 800-53 Rev 5.1.1: SR-01
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-18
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: PM-31
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AT-01
  • SP 800-53 Rev 5.2.0: AU-01
  • SP 800-53 Rev 5.2.0: CA-01
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP 800-53 Rev 5.2.0: MA-01
  • SP 800-53 Rev 5.2.0: MP-01
  • SP 800-53 Rev 5.2.0: PE-01
  • SP 800-53 Rev 5.2.0: PL-01
  • SP 800-53 Rev 5.2.0: PM-01
  • SP 800-53 Rev 5.2.0: PS-01
  • SP 800-53 Rev 5.2.0: PT-01
  • SP 800-53 Rev 5.2.0: RA-01
  • SP 800-53 Rev 5.2.0: SA-01
  • SP 800-53 Rev 5.2.0: SC-01
  • SP 800-53 Rev 5.2.0: SI-01
  • SP 800-53 Rev 5.2.0: SR-01
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-18
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: PM-31
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: RA-03
  • SP 800-53 Rev 5.2.0: RA-07
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SSDF: PW.4.1

GV.SC-04

Suppliers are known and prioritized by criticality

Implementation Examples

  • Ex1: Develop criteria for supplier criticality based on, for example, the sensitivity of data processed or possessed by suppliers, the degree of access to the organization's systems, and the importance of the products or services to the organization's mission
  • Ex2: Keep a record of all suppliers, and prioritize suppliers based on the criticality criteria

Informative References

  • CCMv4.0: STA-07
  • CIS Controls v8.0: 15.1
  • CIS Controls v8.0: 15.3
  • CIS Controls v8.1: 15.1
  • CIS Controls v8.1: 15.3
  • CRI Profile v2.0: GV.SC-04
  • CRI Profile v2.0: GV.SC-04.01
  • CSF v1.1: ID.SC-2
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.22
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.4
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.2
  • PCI DSS: 12.5.2
  • PCI DSS: 1.2.4
  • PCI DSS: 6.3.2
  • SCF: AST-01
  • SCF: TPM-01
  • SCF: TPM-02
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-221A: GV.CT-2
  • SP 800-221A: GV.CT-3
  • SP 800-53 Rev 5.1.1: RA-09
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: RA-09
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System

GV.SC-05

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Implementation Examples

  • Ex1: Establish security requirements for suppliers, products, and services commensurate with their criticality level and potential impact if compromised
  • Ex2: Include all cybersecurity and supply chain requirements that third parties must follow and how compliance with the requirements may be verified in default contractual language
  • Ex3: Define the rules and protocols for information sharing between the organization and its suppliers and sub-tier suppliers in agreements
  • Ex4: Manage risk by including security requirements in agreements based on their criticality and potential impact if compromised
  • Ex5: Define security requirements in service-level agreements (SLAs) for monitoring suppliers for acceptable security performance throughout the supplier relationship lifecycle
  • Ex6: Contractually require suppliers to disclose cybersecurity features, functions, and vulnerabilities of their products and services for the life of the product or the term of service
  • Ex7: Contractually require suppliers to provide and maintain a current component inventory (e.g., software or hardware bill of materials) for critical products
  • Ex8: Contractually require suppliers to vet their employees and guard against insider threats
  • Ex9: Contractually require suppliers to provide evidence of performing acceptable security practices through, for example, self-attestation, conformance to known standards, certifications, or inspections
  • Ex10: Specify in contracts and other agreements the rights and responsibilities of the organization, its suppliers, and their supply chains, with respect to potential cybersecurity risks

Informative References

  • CCMv4.0: CCC-05
  • CCMv4.0: CEK-08
  • CCMv4.0: DSP-13
  • CCMv4.0: DSP-14
  • CCMv4.0: IPY-04
  • CCMv4.0: STA-02
  • CCMv4.0: STA-03
  • CCMv4.0: STA-04
  • CCMv4.0: STA-08
  • CCMv4.0: STA-09
  • CCMv4.0: STA-12
  • CCMv4.0: STA-13
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 15.4
  • CIS Controls v8.1: 15.4
  • CRI Profile v2.0: EX.CN
  • CRI Profile v2.0: EX.CN-01
  • CRI Profile v2.0: EX.CN-02
  • CRI Profile v2.0: EX.CN-01.01
  • CRI Profile v2.0: EX.CN-01.02
  • CRI Profile v2.0: EX.CN-01.03
  • CRI Profile v2.0: EX.CN-02.01
  • CRI Profile v2.0: EX.CN-02.02
  • CRI Profile v2.0: EX.CN-02.03
  • CRI Profile v2.0: EX.CN-02.04
  • CSF v1.1: ID.SC-3
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2 (a)
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • ISO/IEC 27001:2022: Control 5.20
  • NICE Framework: IO-WRL-003
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.8.2
  • PCI DSS: 12.9.1
  • PCI DSS: 12.9.2
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.1
  • SCF: CPL-01
  • SCF: RSK-01
  • SCF: RSK-09
  • SCF: TPM-05
  • SCF: TPM-05.2
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.1.1: SR-10
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-05
  • SP 800-53 Rev 5.2.0: SR-06
  • SP 800-53 Rev 5.2.0: SR-10
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SSDF: PO.1.3

GV.SC-06

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Implementation Examples

  • Ex1: Perform thorough due diligence on prospective suppliers that is consistent with procurement planning and commensurate with the level of risk, criticality, and complexity of each supplier relationship
  • Ex2: Assess the suitability of the technology and cybersecurity capabilities and the risk management practices of prospective suppliers
  • Ex3: Conduct supplier risk assessments against business and applicable cybersecurity requirements
  • Ex4: Assess the authenticity, integrity, and security of critical products prior to acquisition and use

Informative References

  • CCMv4.0: STA-01
  • CCMv4.0: STA-08
  • CCMv4.0: STA-11
  • CIS Controls v8.0: 15.5
  • CIS Controls v8.1: 15.5
  • CRI Profile v2.0: EX.DD
  • CRI Profile v2.0: EX.DD-01
  • CRI Profile v2.0: EX.DD-02
  • CRI Profile v2.0: EX.DD-01.01
  • CRI Profile v2.0: EX.DD-01.02
  • CRI Profile v2.0: EX.DD-01.03
  • CRI Profile v2.0: EX.DD-02.01
  • CRI Profile v2.0: EX.DD-02.02
  • CRI Profile v2.0: EX.DD-02.03
  • CRI Profile v2.0: EX.DD-02.04
  • CSF v1.1: ID.SC-1
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2 (a)
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-006
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.2
  • PCI DSS: 12.5.2
  • PCI DSS: 1.2.4
  • PCI DSS: 1.2.3
  • SCF: TPM-01
  • SCF: TPM-02
  • SCF: TPM-03
  • SCF: TPM-03.2
  • SCF: TPM-03.3
  • SCF: TPM-04
  • SCF: TPM-04.1
  • SCF: TPM-04.3
  • SCF: TPM-04.4
  • SCF: TPM-05
  • SCF: TPM-05.2
  • SCF: TPM-05.4
  • SCF: TPM-05.7
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-05
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System

GV.SC-07

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

Implementation Examples

  • Ex1: Adjust assessment formats and frequencies based on the third party's reputation and the criticality of the products or services they provide
  • Ex2: Evaluate third parties' evidence of compliance with contractual cybersecurity requirements, such as self-attestations, warranties, certifications, and other artifacts
  • Ex3: Monitor critical suppliers to ensure that they are fulfilling their security obligations throughout the supplier relationship lifecycle using a variety of methods and techniques, such as inspections, audits, tests, or other forms of evaluation
  • Ex4: Monitor critical suppliers, services, and products for changes to their risk profiles, and reevaluate supplier criticality and risk impact accordingly
  • Ex5: Plan for unexpected supplier and supply chain-related interruptions to ensure business continuity

Informative References

  • CCMv4.0: STA-01
  • CCMv4.0: STA-08
  • CCMv4.0: STA-10
  • CCMv4.0: STA-11
  • CCMv4.0: STA-12
  • CCMv4.0: STA-13
  • CCMv4.0: STA-14
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 15.6
  • CIS Controls v8.1: 15.6
  • CRI Profile v2.0: EX.MM
  • CRI Profile v2.0: EX.MM-01
  • CRI Profile v2.0: EX.MM-02
  • CRI Profile v2.0: EX.MM-01.01
  • CRI Profile v2.0: EX.MM-01.02
  • CRI Profile v2.0: EX.MM-01.03
  • CRI Profile v2.0: EX.MM-01.04
  • CRI Profile v2.0: EX.MM-01.05
  • CRI Profile v2.0: EX.MM-01.06
  • CRI Profile v2.0: EX.MM-02.01
  • CRI Profile v2.0: EX.MM-02.02
  • CRI Profile v2.0: EX.MM-02.03
  • CSF v1.1: ID.SC-2
  • CSF v1.1: ID.SC-4
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.31
  • ISO/IEC 27001:2022: Control 5.22
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.8.4
  • PCI DSS: 12.9.2
  • PCI DSS: 12.9.1
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.3
  • PCI DSS: 12.8.1
  • PCI DSS: 12.5.2
  • PCI DSS: 1.2.4
  • PCI DSS: 6.3.2
  • PCI DSS: 6.3.1
  • PCI DSS: 6.4.3
  • PCI DSS: 11.6.1
  • SCF: TPM-01
  • SCF: TPM-02
  • SCF: TPM-03
  • SCF: TPM-03.2
  • SCF: TPM-03.3
  • SCF: TPM-04
  • SCF: TPM-04.1
  • SCF: TPM-08
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.CT-2
  • SP 800-221A: GV.CT-3
  • SP 800-221A: MA.RM-2
  • SP 800-221A: MA.RM-3
  • SP 800-53 Rev 5.1.1: RA-09
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: RA-09
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
  • SP-800-37 Rev 2: RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System
  • SP-800-37 Rev 2: RMF Assess Step: TASK A-3 Control Assessments
  • SP-800-37 Rev 2: RMF Assess Step: TASK A-5 Remediation Actions
  • SP-800-37 Rev 2: RMF Assess Step: TASK A-6 Plan of Action and Milestones
  • SP-800-37 Rev 2: RMF Authorize Step: TASK R-2 Risk Analysis and Determination
  • SP-800-37 Rev 2: RMF Authorize Step: TASK R-3 Risk Response
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-1 System and Environment Changes
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-2 Ongoing Assessments
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
  • SSDF: PW.4.1
  • SSDF: PW.4.4

GV.SC-08

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

Implementation Examples

  • Ex1: Define and use rules and protocols for reporting incident response and recovery activities and the status between the organization and its suppliers
  • Ex2: Identify and document the roles and responsibilities of the organization and its suppliers for incident response
  • Ex3: Include critical suppliers in incident response exercises and simulations
  • Ex4: Define and coordinate crisis communication methods and protocols between the organization and its critical suppliers
  • Ex5: Conduct collaborative lessons learned sessions with critical suppliers

Informative References

  • CCMv4.0: BCR-06
  • CCMv4.0: BCR-07
  • CCMv4.0: DSP-18
  • CCMv4.0: SEF-03
  • CCMv4.0: SEF-04
  • CCMv4.0: SEF-07
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 15.4
  • CIS Controls v8.1: 15.4
  • CRI Profile v2.0: GV.SC-08
  • CRI Profile v2.0: GV.SC-08.01
  • CSF v1.1: ID.SC-5
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.26
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-003
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.10.5
  • PCI DSS: 12.10.1
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.1
  • PCI DSS: 1.2.4
  • PCI DSS: 1.2.3
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.6
  • PCI DSS: 12.8.2
  • PCI DSS: 12.9.1
  • SCF: BCD-01
  • SCF: BCD-01.2
  • SCF: IRO-01
  • SCF: IRO-02
  • SCF: IRO-02.5
  • SCF: TPM-01
  • SCF: TPM-02
  • SCF: TPM-10
  • SCF: TPM-11
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.06.01
  • SP 800-171 Rev 3: 03.06.02
  • SP 800-171 Rev 3: 03.06.05
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.CT-3
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-08
  • SP 800-53 Rev 5.1.1: CP-01
  • SP 800-53 Rev 5.1.1: IR-01
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-08
  • SP 800-53 Rev 5.2.0: CP-01
  • SP 800-53 Rev 5.2.0: IR-01
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-1 System and Environment Changes
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response

GV.SC-09

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

Implementation Examples

  • Ex1: Policies and procedures require provenance records for all acquired technology products and services
  • Ex2: Periodically provide risk reporting to leaders about how acquired components are proven to be untampered and authentic
  • Ex3: Communicate regularly among cybersecurity risk managers and operations personnel about the need to acquire software patches, updates, and upgrades only from authenticated and trustworthy software providers
  • Ex4: Review policies to ensure that they require approved supplier personnel to perform maintenance on supplier products
  • Ex5: Policies and procedure require checking upgrades to critical hardware for unauthorized changes

Informative References

  • CCMv4.0: STA-11
  • CCMv4.0: STA-12
  • CIS Controls v8.0: 15.6
  • CIS Controls v8.1: 15.6
  • CRI Profile v2.0: GV.SC-09
  • CRI Profile v2.0: GV.SC-09.01
  • CSF v1.1: ID.SC-1
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.21
  • ISO/IEC 27001:2022: Annex A Controls: 5.22
  • NICE Framework: DD-WRL-001
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 6.4.3
  • PCI DSS: 9.5.1.1
  • PCI DSS: 9.5.1.2
  • PCI DSS: 9.5.1.2.1
  • PCI DSS: 6.3.1
  • PCI DSS: 6.3.3
  • PCI DSS: 11.6.1
  • PCI DSS: 6.2.3
  • PCI DSS: 12.3.4
  • PCI DSS: 12.8.4
  • PCI DSS: 6.3.2
  • PCI DSS: 12.8.1
  • PCI DSS: 12.8.5
  • SCF: GOV-01
  • SCF: GOV-05
  • SCF: PRM-07
  • SCF: RSK-01
  • SCF: RSK-09
  • SCF: RSK-09.1
  • SCF: SEA-07.1
  • SCF: TDA-01.1
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.1.1: PM-19
  • SP 800-53 Rev 5.1.1: PM-28
  • SP 800-53 Rev 5.1.1: PM-30
  • SP 800-53 Rev 5.1.1: PM-31
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-53 Rev 5.2.0: PM-19
  • SP 800-53 Rev 5.2.0: PM-28
  • SP 800-53 Rev 5.2.0: PM-30
  • SP 800-53 Rev 5.2.0: PM-31
  • SP 800-53 Rev 5.2.0: RA-03
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-05
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O

GV.SC-10

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Implementation Examples

  • Ex1: Establish processes for terminating critical relationships under both normal and adverse circumstances
  • Ex2: Define and implement plans for component end-of-life maintenance support and obsolescence
  • Ex3: Verify that supplier access to organization resources is deactivated promptly when it is no longer needed
  • Ex4: Verify that assets containing the organization's data are returned or properly disposed of in a timely, controlled, and safe manner
  • Ex5: Develop and execute a plan for terminating or transitioning supplier relationships that takes supply chain security risk and resiliency into account
  • Ex6: Mitigate risks to data and systems created by supplier termination
  • Ex7: Manage data leakage risks associated with supplier termination

Informative References

  • CCMv4.0: DSP-02
  • CCMv4.0: DSP-16
  • CCMv4.0: HRS-05
  • CCMv4.0: IAM-07
  • CCMv4.0: IPY-04
  • CCMv4.0: SEF-04
  • CIS Controls v8.0: 15.7
  • CIS Controls v8.1: 15.7
  • CRI Profile v2.0: EX.TR
  • CRI Profile v2.0: EX.TR-01
  • CRI Profile v2.0: EX.TR-02
  • CRI Profile v2.0: EX.TR-01.01
  • CRI Profile v2.0: EX.TR-01.02
  • CRI Profile v2.0: EX.TR-01.03
  • CRI Profile v2.0: EX.TR-02.01
  • CSF v1.1: ID.SC-1
  • CoP: A4
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.2
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.19
  • ISO/IEC 27001:2022: Annex A Controls: 5.20
  • ISO/IEC 27001:2022: Annex A Controls: 5.21
  • ISO/IEC 27001:2022: Annex A Controls: 5.22
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-009
  • NICE Framework: OG-WRL-012
  • NICE Framework: OG-WRL-015
  • NICE Framework: OG-WRL-016
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 12.8.2
  • PCI DSS: 12.8.5
  • PCI DSS: 12.8.3
  • PCI DSS: 8.2.5
  • PCI DSS: 9.3.1.1
  • PCI DSS: 12.3.4
  • PCI DSS: 6.4.3
  • PCI DSS: 12.10.1
  • PCI DSS: 12.5.2
  • PCI DSS: 1.2.4
  • PCI DSS: 1.2.3
  • PCI DSS: 3.2.1
  • PCI DSS: 9.4.7
  • PCI DSS: 9.4.6
  • SCF: RSK-09
  • SCF: TPM-01
  • SCF: TPM-05.2
  • SP 800-171 Rev 3: 03.11.01
  • SP 800-171 Rev 3: 03.11.02
  • SP 800-171 Rev 3: 03.11.04
  • SP 800-171 Rev 3: 03.14.08
  • SP 800-171 Rev 3: 03.16.03
  • SP 800-171 Rev 3: 03.17.01
  • SP 800-171 Rev 3: 03.17.02
  • SP 800-171 Rev 3: 03.17.03
  • SP 800-221A: GV.PO-1
  • SP 800-53 Rev 5.1.1: PM-31
  • SP 800-53 Rev 5.1.1: RA-03
  • SP 800-53 Rev 5.1.1: RA-05
  • SP 800-53 Rev 5.1.1: RA-07
  • SP 800-53 Rev 5.1.1: SA-04
  • SP 800-53 Rev 5.1.1: SA-09
  • SP 800-53 Rev 5.1.1: SR-02
  • SP 800-53 Rev 5.1.1: SR-03
  • SP 800-53 Rev 5.1.1: SR-05
  • SP 800-53 Rev 5.1.1: SR-06
  • SP 800-53 Rev 5.2.0: PM-31
  • SP 800-53 Rev 5.2.0: RA-03
  • SP 800-53 Rev 5.2.0: RA-05
  • SP 800-53 Rev 5.2.0: RA-07
  • SP 800-53 Rev 5.2.0: SA-04
  • SP 800-53 Rev 5.2.0: SA-09
  • SP 800-53 Rev 5.2.0: SR-02
  • SP 800-53 Rev 5.2.0: SR-03
  • SP 800-53 Rev 5.2.0: SR-05
  • SP 800-53 Rev 5.2.0: SR-06
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition
  • SP-800-37 Rev 2: RMF Monitor Step: TASK M-7 System Disposal