id: "GV.PO-01" title: "Cybersecurity Policy" function: "GV" function_name: "Govern" category: "GV.PO" category_name: "Cybersecurity Policy" description: "Cybersecurity policy is established, communicated, and enforced." controls: - AC-1 - AT-1 - AU-1 - CM-1 - CP-1 - IA-1 - IR-1 - MA-1 - MP-1 - PE-1 - PL-1 - PM-1 - PM-2 - PM-3 - PM-9 - PS-1 - RA-1 - SA-1 - SC-1 - SI-1
GV.PO-01: Cybersecurity Policy
Description
Cybersecurity policy is established, communicated, and enforced.
Category Context
Function: GV — Govern Category: GV.PO — Cybersecurity Policy
Cybersecurity policies, processes, and procedures are established and maintained.
Mapped SP 800-53 Controls
- AC-1 (Access Control) — View Control
- AT-1 (Awareness and Training) — View Control
- AU-1 (Audit and Accountability) — View Control
- CM-1 (Configuration Management) — View Control
- CP-1 (Contingency Planning) — View Control
- IA-1 (Identification and Authentication) — View Control
- IR-1 (Incident Response) — View Control
- MA-1 (Maintenance) — View Control
- MP-1 (Media Protection) — View Control
- PE-1 (Physical and Environmental Protection) — View Control
- PL-1 (Planning) — View Control
- PM-1 (Program Management) — View Control
- PM-2 (Program Management) — View Control
- PM-3 (Program Management) — View Control
- PM-9 (Program Management) — View Control
- PS-1 (Personnel Security) — View Control
- RA-1 (Risk Assessment) — View Control
- SA-1 (System and Services Acquisition) — View Control
- SC-1 (System and Communications Protection) — View Control
- SI-1 (System and Information Integrity) — View Control