GV.OC-03.006
Has your organization documented how its cybersecurity strategy addresses applicable legal, regulatory, and contractual requirements?
Explanation
This question assesses whether your organization has formally mapped its cybersecurity controls and practices to the specific legal and regulatory frameworks it must comply with (such as GDPR, HIPAA, PCI DSS, etc.) and any contractual obligations to customers or partners. Without this alignment, organizations risk non-compliance penalties, contractual breaches, and security gaps in areas mandated by law or agreements. Evidence could include a compliance matrix or document that maps specific cybersecurity controls to regulatory requirements, showing how each requirement is addressed by the organization's security program. This might be a spreadsheet or formal document that lists each applicable regulation/contract clause alongside the corresponding security control, policy, or procedure implemented to satisfy it.
Implementation Example
Align the organization's cybersecurity strategy with legal, regulatory, and contractual requirements
ID: GV.OC-03.006
Context
- Function
- GV: GOVERN
- Category
- GV.OC: Organizational Context
- Sub-Category
- Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

