Skip to main content

πŸ’Ό GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders

  • Contextual name: πŸ’Ό GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders
  • ID: /frameworks/nist-csf-v2.0/gv-rm/01
  • Located in: πŸ’Ό Risk Management Strategy (GV.RM)

Description​

  1. Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur
  2. Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control systems)
  3. Senior leaders agree about cybersecurity objectives and use them for measuring and managing risk and performance

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-rm/01
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/ra/07
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-9 Risk Management Strategy
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό RA-7 Risk Response
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags