Skip to main content

💼 Policy (GV.PO)

  • ID: /frameworks/nist-csf-v2.0/gv-po

Description​

Organizational cybersecurity policy is established, communicated, and enforced

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced3no data
💼 GV.PO-02: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission3no data