GV.RM-03 GV · Govern · GV.RM Risk Management Strategy

GV.RM-03 — Cyber risk in enterprise risk management

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.

Also written as GV-RM-03, GV.RM-3, CSF 2.0 GV.RM-03, NIST CSF GV.RM.

What NIST CSF GV.RM-03 means

GV.RM-03 is one of 31 subcategories in the Govern (GV) function, under the Risk Management Strategy category (GV.RM). The Core states: “Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.” Govern is the function CSF 2.0 added, and it is the one most organisations score lowest on: the outcome is not a tool you deploy but a decision someone with authority has to make, record, and revisit.

Evidence that supports GV.RM-03

To demonstrate this outcome in an assessment or audit, gather artefacts such as:

  • Cyber risks recorded in the enterprise risk register
  • ERM committee minutes covering cyber risk
  • Common risk scoring methodology across risk types

ISO 27001 mapping

GV.RM-03 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.8. Evidence collected for one framework typically supports the other.

Map GV.RM-03 to ISO 27001 & SOC 2 →
Crosswalk this subcategory in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against GV.RM-03 in the Risk Register.

Other Risk Management Strategy subcategories

GV.RM-01 Risk management objectives GV.RM-02 Risk appetite and tolerance GV.RM-04 Risk response direction GV.RM-05 Risk communication lines GV.RM-06 Standardized risk measurement GV.RM-07 Strategic opportunities

All 31 Govern subcategories →

Frequently asked questions

Is NIST CSF GV.RM-03 mandatory?

No. CSF 2.0 is a voluntary framework of outcomes rather than a set of requirements, and there is no certification against it. GV.RM-03 becomes binding only when something else makes it so — a contract, a regulator that references CSF, or your own Target Profile. That is the practical difference between CSF and an auditable standard like ISO 27001 or SOC 2.

How is GV.RM-03 assessed?

Through profiles rather than pass/fail testing. You record how fully the outcome is achieved today in a Current Profile, state where it needs to be in a Target Profile, and the gap between them becomes your action plan. Implementation Tiers (Partial, Risk Informed, Repeatable, Adaptive) describe how rigorous your governance around the outcome is, not whether you have met it.

Who owns GV.RM-03?

Govern outcomes sit with leadership rather than with the security team — executives, risk owners, and in many organisations the board. If GV.RM-03 has no named owner outside IT, that is usually the finding, because CSF 2.0 introduced Govern precisely to make cybersecurity a management-level accountability.

Does NIST CSF GV.RM-03 map to ISO 27001?

Yes — GV.RM-03 corresponds to ISO 27001:2022 Annex A control(s) A.5.8. Evidence collected for one framework typically supports the other, so a single control library can serve both.