GV.PO-01.052
Has your organization formally documented and communicated its cybersecurity risk management policy, processes, and procedures to all relevant stakeholders?
Explanation
This question assesses whether your organization has established clear cybersecurity risk management guidance and effectively shared it throughout the organization. Proper communication ensures all employees understand their roles in managing cybersecurity risks, the procedures to follow, and how risk decisions are made within the organization. Evidence could include: distribution logs of policy documents, intranet screenshots showing where policies are published, training records covering risk management procedures, signed acknowledgments from employees, or meeting minutes where policies were presented and discussed.
Implementation Example
Communicate cybersecurity risk management policy and supporting processes and procedures across the organization
ID: GV.PO-01.052
Context
- Function
- GV: GOVERN
- Category
- GV.PO: Policy
- Sub-Category
- Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

