Skip to main content

💼 GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

  • ID: /frameworks/nist-csf-v2.0/gv-rr/02

Description​

  1. Document risk management roles and responsibilities in policy
  2. Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
  3. Include cybersecurity responsibilities and performance requirements in personnel descriptions
  4. Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement
  5. Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-am/06
    • /frameworks/nist-csf-v1.1/id-gv/02
    • /frameworks/nist-csf-v1.1/de-dp/01
    • /frameworks/nist-sp-800-53-r5/pm/02
    • /frameworks/nist-sp-800-53-r5/pm/13
    • /frameworks/nist-sp-800-53-r5/pm/19
    • /frameworks/nist-sp-800-53-r5/pm/23
    • /frameworks/nist-sp-800-53-r5/pm/24
    • /frameworks/nist-sp-800-53-r5/pm/29

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountabilityno data
💼 NIST CSF v1.1 → 💼 ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are establishedno data
💼 NIST CSF v1.1 → 💼 ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partnersno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-2 Information Security Program Leadership Roleno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-13 Security and Privacy Workforceno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-19 Privacy Program Leadership Roleno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-23 Data Governance Bodyno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-24 Data Integrity Boardno data
💼 NIST SP 800-53 Revision 5 → 💼 PM-29 Risk Management Program Leadership Rolesno data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance