| name | Risk Management Strategy (GV.RM)_risk-management-strategy |
| description | The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support |
| category | configuration |
| version | 2.0 |
| author | cyberstrike-official |
| tags | ["nist","csf","v2.0","risk management strategy (gv-rm)","gv","category"] |
| tech_stack | ["any"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Risk Management Strategy (GV.RM) Risk Management Strategy
High-Level Description
Function: GOVERN (GV)
Framework: NIST Cybersecurity Framework v2.0
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
What to Check
How to Test
Step 1: Identify Current Profile
Determine the organization's current and target CSF profile tier for Risk Management Strategy (GV.RM).
Step 2: Assess Outcome Achievement
# Review organizational policies and procedures
# Check for evidence that Risk Management Strategy (GV.RM) outcome is met
# Interview stakeholders responsible for GOVERN
Step 3: Map to Technical Controls
Identify which SP 800-53 controls implement this CSF outcome and verify their operating effectiveness.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Assess cloud security posture | cloud_audit_* tools |
| Manual Review | Policy and procedure review | Interviews and documentation |
Remediation Guide
Achieve the Risk Management Strategy (GV.RM) Risk Management Strategy outcome:
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
Risk Assessment
| Finding | Severity | Impact |
|---|
| Risk Management Strategy (GV.RM) Risk Management Strategy outcome not achieved | Medium | GOVERN Function Gap |
CWE Categories
| CWE ID | Title |
|---|
| N/A | No direct CWE mapping |