Skip to main content

πŸ’Ό GV.RM-04: Strategic direction that describes appropriate risk response options is established and communicated

  • Contextual name: πŸ’Ό GV.RM-04: Strategic direction that describes appropriate risk response options is established and communicated
  • ID: /frameworks/nist-csf-v2.0/gv-rm/04
  • Located in: πŸ’Ό Risk Management Strategy (GV.RM)

Description​

  1. Specify criteria for accepting and avoiding cybersecurity risk for various classifications of data
  2. Determine whether to purchase cybersecurity insurance
  3. Document conditions under which shared responsibility models are acceptable (e.g., outsourcing certain cybersecurity functions, having a third party perform financial transactions on behalf of the organization, using public cloud-based services)

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-rm/02
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/pm/28
    • /frameworks/nist-sp-800-53-r5/pm/30
    • /frameworks/nist-sp-800-53-r5/sr/02

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.RM-2: Organizational risk tolerance is determined and clearly expressed
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-9 Risk Management Strategy
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-28 Risk Framing
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-30 Supply Chain Risk Management Strategy1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SR-2 Supply Chain Risk Management Plan1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags