Skip to main content

πŸ’Ό GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

  • Contextual name: πŸ’Ό GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • ID: /frameworks/nist-csf-v2.0/gv-rm/03
  • Located in: πŸ’Ό Risk Management Strategy (GV.RM)

Description​

  1. Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety)
  2. Include cybersecurity risk managers in enterprise risk management planning
  3. Establish criteria for escalating cybersecurity risks within enterprise risk management

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-gv/04
    • /frameworks/nist-sp-800-53-r5/pm/03
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/pm/30
    • /frameworks/nist-sp-800-53-r5/ra/07
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.GV-4: Governance and risk management processes address cybersecurity risks
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-3 Information Security and Privacy Resources
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-9 Risk Management Strategy
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-30 Supply Chain Risk Management Strategy1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό RA-7 Risk Response
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags