|
controlPM-9

Risk Management Strategy (PM-9)

Develops a comprehensive strategy to manage: Implement the risk management strategy consistently across the organization; and Review and update the risk management strategy [organization-defined] or as required, to address organizational changes.

program-managementgovernancestrategy

Why These Connect

Maps To35

These are equivalent or closely aligned requirements in other frameworks.

Supports63

These related controls work together — a change to one may affect the others.

Related Controls(41)

AC-1Policy and Procedures (AC-1)
LMH
AT-1Policy and Procedures (AT-1)
LMH
AU-1Policy and Procedures (AU-1)
LMH
CA-1Policy and Procedures (CA-1)
LMH
CA-2Control Assessments (CA-2)
LMH
CA-5Plan of Action and Milestones (CA-5)
LMH
CA-6Authorization (CA-6)
LMH
CA-7Continuous Monitoring (CA-7)
LMH
CM-1Policy and Procedures (CM-1)
LMH
CP-1Policy and Procedures (CP-1)
LMH
IA-1Policy and Procedures (IA-1)
LMH
IR-1Policy and Procedures (IR-1)
LMH
MA-1Policy and Procedures (MA-1)
LMH
MP-1Policy and Procedures (MP-1)
LMH
PE-1Policy and Procedures (PE-1)
LMH
PE-23Facility Location (PE-23)PL-1Policy and Procedures (PL-1)
LMH
PL-2System Security and Privacy Plans (PL-2)
LMH
PL-9Central Management (PL-9)PM-6Measures of Performance (PM-6)PM-8Critical Infrastructure Plan (PM-8)PM-2Information Security Program Leadership Role (PM-2)PM-18Privacy Program Plan (PM-18)PM-28Risk Framing (PM-28)PM-30Supply Chain Risk Management Strategy (PM-30)PS-1Policy and Procedures (PS-1)
LMH
PT-1Policy and Procedures (PT-1)PT-2Authority to Process Personally Identifiable Information (PT-2)PT-3Personally Identifiable Information Processing Purposes (PT-3)RA-1Policy and Procedures (RA-1)
LMH
RA-3Risk Assessment (RA-3)
LMH
RA-9Criticality Analysis (RA-9)
MH
SA-1Policy and Procedures (SA-1)
LMH
SA-4Acquisition Process (SA-4)
LMH
SC-1Policy and Procedures (SC-1)
LMH
SC-38Operations Security (SC-38)SI-1Policy and Procedures (SI-1)
LMH
SI-12Information Management and Retention (SI-12)
LMH
SR-1Policy and Procedures (SR-1)
LMH
SR-2Supply Chain Risk Management Plan (SR-2)
LMH
PM-31Continuous Monitoring Strategy (PM-31)

Cross-Framework Mappings(35)

GV.OV-01GV.OV-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-02GV.OV-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-03GV.SC-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-04ID.RA-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-06ID.RA-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-01GV.RM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-02GV.RM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-02GV.OC-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-03GV.RM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-04GV.RM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-05GV.RM-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-06GV.RM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.IR-04PR.IR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-07GV.RM-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.AE-04DE.AE-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-04RC.RP-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20229 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
GV.OV-01GV.OV-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OV-02GV.OV-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-03GV.SC-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-04ID.RA-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-06ID.RA-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-01GV.RM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-02GV.RM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-02GV.OC-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-03GV.RM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-04GV.RM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-05GV.RM-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-06GV.RM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.IR-04PR.IR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RM-07GV.RM-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.AE-04DE.AE-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
RC.RP-04RC.RP-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5