GV.RM-01 GV · Govern · GV.RM Risk Management Strategy

GV.RM-01 — Risk management objectives

Risk management objectives are established and agreed to by organizational stakeholders.

Also written as GV-RM-01, GV.RM-1, CSF 2.0 GV.RM-01, NIST CSF GV.RM.

What NIST CSF GV.RM-01 means

GV.RM-01 is one of 31 subcategories in the Govern (GV) function, under the Risk Management Strategy category (GV.RM). The Core states: “Risk management objectives are established and agreed to by organizational stakeholders.” Govern is the function CSF 2.0 added, and it is the one most organisations score lowest on: the outcome is not a tool you deploy but a decision someone with authority has to make, record, and revisit.

Evidence that supports GV.RM-01

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Documented cyber risk management objectives approved by leadership
  • Objective review records on defined cadence
  • Alignment of objectives to enterprise risk management

How to implement GV.RM-01

  1. Write objectives that can be judged, not aspirations"Improve our security posture" cannot be assessed. "Reduce mean time to remediate critical internet-facing vulnerabilities to under seven days" can. The outcome asks for objectives that stakeholders agree to, which implies they are specific enough to disagree about.
  2. Get genuine agreement from outside securityThe word in the outcome is agreed. That means finance, legal and the business owners have accepted the objectives, not just been told them. Meeting minutes or a signed strategy document evidence this far better than a slide deck.
  3. Anchor them to enterprise risk, not to a control frameworkCyber risk objectives that reference only technical controls signal a programme disconnected from the business. Tie each objective to a business consequence — service availability, regulatory exposure, contractual commitment — which is what the Govern function was added to force.
  4. Set a review cadence and honour itObjectives that were agreed once and never revisited score low on Implementation Tier even when they are good objectives. Annual review with recorded outcomes is the practical minimum.
  5. Express risk appetite in usable termsAppetite is what turns objectives into decisions. Stated as thresholds — what level of residual risk can be accepted, by whom, up to what value — it becomes something a team can act on rather than a paragraph in a policy.

Common assessment findings for GV.RM-01

What actually gets raised against GV.RM-01, in rough order of how often it comes up:

Assessing GV.RM-01 in a profile

At Tier 1 (Partial) objectives are informal and inconsistently applied. At Tier 2 (Risk Informed) they exist and are approved but are not organisation-wide. Tier 3 (Repeatable) requires them to be formally established as policy and updated on change. Tier 4 (Adaptive) expects them to adapt continuously from lessons learned and predictive indicators.

ISO 27001 mapping

GV.RM-01 has no direct one-to-one ISO 27001:2022 Annex A equivalent — it is a governance or process outcome that ISO 27001 addresses at the management-system level (Clauses 4–10) rather than through a specific Annex A control. Treat it as its own requirement in your CSF profile.

Map GV.RM-01 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against GV.RM-01 in the Risk Register.

Other Risk Management Strategy subcategories

GV.RM-02 Risk appetite and tolerance GV.RM-03 Cyber risk in enterprise risk management GV.RM-04 Risk response direction GV.RM-05 Risk communication lines GV.RM-06 Standardized risk measurement GV.RM-07 Strategic opportunities

All 31 Govern subcategories →

Frequently asked questions

Is NIST CSF GV.RM-01 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. GV.RM-01 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is GV.RM-01 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns GV.RM-01?

Govern outcomes sit with leadership rather than with the security team — executives, risk owners, and in many organisations the board. If GV.RM-01 has no named owner outside IT, that is usually the finding, because CSF 2.0 introduced Govern precisely to make cybersecurity a management-level accountability.

What are the most common audit findings for GV.RM-01?

Objectives written by the security team and never formally agreed by anyone else, failing the core of the outcome. Objectives with no measurable form, making current-versus-target assessment impossible.