💼 GV.RR-02: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
- ID:
/frameworks/nist-csf-v2.0/gv-rr/02
Stats​
not available
Description​
- Document risk management roles and responsibilities in policy
- Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
- Include cybersecurity responsibilities and performance requirements in personnel descriptions
- Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement
- Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions
Similar​
- Sections
/frameworks/nist-csf-v1.1/id-am/06/frameworks/nist-csf-v1.1/id-gv/02/frameworks/nist-csf-v1.1/de-dp/01/frameworks/nist-sp-800-53-r5/pm/02/frameworks/nist-sp-800-53-r5/pm/13/frameworks/nist-sp-800-53-r5/pm/19/frameworks/nist-sp-800-53-r5/pm/23/frameworks/nist-sp-800-53-r5/pm/24/frameworks/nist-sp-800-53-r5/pm/29
Similar Sections (Take Policies From)​
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|