Skip to main content

πŸ’Ό GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

  • Contextual name: πŸ’Ό GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • ID: /frameworks/nist-csf-v2.0/gv-rr/02
  • Located in: πŸ’Ό Roles, Responsibilities, and Authorities (GV.RR)

Description​

  1. Document risk management roles and responsibilities in policy
  2. Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
  3. Include cybersecurity responsibilities and performance requirements in personnel descriptions
  4. Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement
  5. Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-am/06
    • /frameworks/nist-csf-v1.1/id-gv/02
    • /frameworks/nist-csf-v1.1/de-dp/01
    • /frameworks/nist-sp-800-53-r5/pm/02
    • /frameworks/nist-sp-800-53-r5/pm/13
    • /frameworks/nist-sp-800-53-r5/pm/19
    • /frameworks/nist-sp-800-53-r5/pm/23
    • /frameworks/nist-sp-800-53-r5/pm/24
    • /frameworks/nist-sp-800-53-r5/pm/29

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-2 Information Security Program Leadership Role
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-13 Security and Privacy Workforce
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-19 Privacy Program Leadership Role
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-23 Data Governance Body
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-24 Data Integrity Board
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-29 Risk Management Program Leadership Roles

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags