GV.OC-03_gvoc-03
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp