GV.PO: Policy
Category is new to this version of the framework and incorporates the following item from the previous version: ID.GV-1: Organizational cybersecurity policy is established and communicated.
Description
Organizational cybersecurity policy is established, communicated, and enforced
Framework Subcategories
GV.PO-01: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
[csf.tools Note: Subcategories do not have detailed descriptions.]
GV.PO-02: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
[csf.tools Note: Subcategories do not have detailed descriptions.]