Policy (GV.PO)
Policy (GV.PO) is a category within the Govern function of the NIST Cybersecurity Framework (CSF) 2.0. It concerns establishing an organizational policy for managing cybersecurity risks and making sure that policy is communicated across the organization and enforced. The policy is meant to reflect the organization's own context, strategy, and priorities rather than a one-size-fits-all rule.
GV.PO is a category under the Govern (GV) function of the NIST Cybersecurity Framework 2.0, issued by the U.S. National Institute of Standards and Technology. It addresses the establishment, communication, and enforcement of policy for managing cybersecurity risks, grounded in organizational context, cybersecurity strategy, and priorities. In CSF 2.0, the category comprises subcategories covering the establishment and communication of the cybersecurity risk management policy (GV.PO-01) and its review, update, and communication as the organization and threat environment change (GV.PO-02). As a governance-pillar construct, GV.PO establishes the policy foundation that directs cybersecurity activities; it does not itself specify technical controls, implementation procedures, or tooling, and its precise application depends on the organization's context, sector, and jurisdiction. Note that GV.PO is distinct from similarly themed CSF 1.1 elements, and 'GV.PO-01' denotes a subcategory rather than the category as a whole.
Why it matters
Policy sits at the foundation of cybersecurity governance because it translates an organization's context, strategy, and priorities into an authoritative statement that directs how cybersecurity risks are to be managed. Without an established and communicated policy, cybersecurity activities tend to be inconsistent, discretionary, and difficult to hold accountable. GV.PO addresses this by requiring not only that a policy exist, but that it be communicated across the organization and enforced, so that the direction set by leadership actually shapes day-to-day behavior rather than remaining a document on a shelf.
Equally important is the requirement that policy be maintained over time. GV.PO-02 addresses the review, update, and communication of the cybersecurity risk management policy as the organization and its threat environment change. This matters because a policy grounded in yesterday's context, strategy, and priorities can become misaligned as the business evolves, as new obligations emerge, or as the threat landscape shifts. Treating policy as a living instrument, rather than a one-time artifact, is central to keeping governance responsive.
As the introductory step in a broader security strategy, a policy framework for managing cybersecurity risks sets a formal foundation on which subsequent activities are built. GV.PO is a governance-pillar construct: it establishes the direction and authority for cybersecurity work, but it does not by itself guarantee any security outcome. Its value depends on downstream implementation, and its precise application varies with the organization's sector and jurisdiction.
Who it's relevant to
Inside GV.PO
Common questions
Answers to the questions practitioners most commonly ask about GV.PO.
