Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.RM-03
Cybersecurity risk management activities and outcomes are included in enterprise risk management processesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RM-03
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) |
Separately, describe in your annual report, under Regulation S-K Item 106, your processes for assessing, identifying and managing material cybersecurity risks and your board's and management's oversight of those risks. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.