Skip to main content

💼 GV.RM-03: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

  • ID: /frameworks/nist-csf-v2.0/gv-rm/03

Description​

  1. Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety)
  2. Include cybersecurity risk managers in enterprise risk management planning
  3. Establish criteria for escalating cybersecurity risks within enterprise risk management

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-gv/04
    • /frameworks/nist-sp-800-53-r5/pm/03
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/pm/30
    • /frameworks/nist-sp-800-53-r5/ra/07
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 ID.GV-4: Governance and risk management processes address cybersecurity risksno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-3 Information Security and Privacy Resourcesno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-9 Risk Management Strategyno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-30 Supply Chain Risk Management Strategy1no data
💼 NIST SP 800-53 Revision 5 → 💼 RA-7 Risk Responseno data
💼 NIST SP 800-53 Revision 5 → 💼 SR-2 Supply Chain Risk Management Plan1no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance