{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework: The NIST Cybersecurity Framework (CSF)","title":"GV.PO-01 - Establishing a Cybersecurity Risk Management Policy ","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/bd6489a3\"></iframe>","width":"100%","height":180,"duration":1188,"description":"GV.PO-01 involves creating a formal cybersecurity risk management policy that reflects the organization’s unique context, strategy, and priorities. This policy outlines management’s intent and expectations, providing a clear framework for security practices that is communicated across all levels. Enforcement ensures that the policy translates into actionable, consistent behavior.\nThis subcategory establishes a foundation for aligning cybersecurity efforts with organizational goals, requiring senior management approval to lend it authority. Regular dissemination and acknowledgment by personnel reinforce its importance and applicability. GV.PO-01 serves as a cornerstone for governance, guiding risk management with a unified approach.","thumbnail_url":"https://img.transistorcdn.com/ZQAUShkq6bmReWtsoCApAiEqnASSjulPAjN3RZCtsFI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTE2/ZTU4ZDc5YjBhMjRj/MDkxMTllN2RmZDU5/YmU2My5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}