GV.RM-01:

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Implementation Examples

Ex1:

Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety)

Ex2:

Include cybersecurity risk managers in enterprise risk management planning

Ex3:

Establish criteria for escalating cybersecurity risks within enterprise risk management