GV.RR-02_gvrr-02
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
Cybersecurity is included in human resources practices
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities