February 2025
Beginner to intermediate
94 pages
1h 27m
English
Previously a category under the Identify function, Govern is now a function in its own right. As a function, Govern is focused on identifying and understanding the regulatory and contractual requirements, dependencies, and other factors that the organization must account for when implementing a cybersecurity program, and on developing the policies, oversight, and governance structure needed to maintain that program effectively.
Organizational context is about understanding the organization’s objectives and operations, and the external and internal factors that affect how it operates. Its first subcategory is to understand the organization’s mission and ensure it informs cybersecurity ...