Skip to main content

💼 GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders

  • Contextual name: 💼 GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders
  • ID: /frameworks/nist-csf-v2.0/gv-rm/01
  • Located in: 💼 Risk Management Strategy (GV.RM)

Description​

  1. Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur
  2. Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control systems)
  3. Senior leaders agree about cybersecurity objectives and use them for measuring and managing risk and performance

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-rm/01
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/ra/07
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
💼 NIST SP 800-53 Revision 5 → 💼 PM-9 Risk Management Strategy
💼 NIST SP 800-53 Revision 5 → 💼 RA-7 Risk Response
💼 NIST SP 800-53 Revision 5 → 💼 SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags