← NIST CSF 2.0 · GOVERN — Organizational Context

GV.OC-01 — Organisational mission is understood and informs risk management

low policy-governancerisk-assessment

Requirement

The organisational mission is understood and informs cybersecurity risk management.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
missionbusiness objectivestrategicbusiness context
Required element 2 — any one of
riskcybersecurityinform
Supporting terms — specificity signals
critical servicepriorityalignmentcrown jewels

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GLBA 314.4(g) Evaluate and adjust the program policy-governance risk-assessment
COPPA 312.8 Written information security program for children's data policy-governance risk-assessment
GDPR Art.5(2) Accountability policy-governance
GDPR Art.24 Responsibility of the controller policy-governance
GDPR Art.31 Cooperation with the supervisory authority policy-governance
GDPR Art.35 Data protection impact assessment risk-assessment
GDPR Art.36 Prior consultation with the supervisory authority risk-assessment
CCPA/CPRA Regs (risk assessments) Risk assessments for significant-risk processing risk-assessment