Skip to main content

πŸ’Ό GV.OV-03: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

  • Contextual name: πŸ’Ό GV.OV-03: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • ID: /frameworks/nist-csf-v2.0/gv-ov/03
  • Located in: πŸ’Ό Oversight (GV.OV)

Description​

  1. Review key performance indicators (KPIs) to ensure that organization-wide policies and procedures achieve objectives
  2. Review key risk indicators (KRIs) to identify risks the organization faces, including likelihood and potential impact
  3. Collect and communicate metrics on cybersecurity risk management with senior leadership

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/pm/04
    • /frameworks/nist-sp-800-53-r5/pm/06
    • /frameworks/nist-sp-800-53-r5/ra/07
    • /frameworks/nist-sp-800-53-r5/sr/06

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-4 Plan of Action and Milestones Process
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-6 Measures of Performance
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό RA-7 Risk Response
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-6 Supplier Assessments and Reviews1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags