Skip to main content
Category: GRC Frameworks

Policy (GV.PO)

Also known as:
Simply put

Policy (GV.PO) is a category within the Govern function of the NIST Cybersecurity Framework (CSF) 2.0. It concerns establishing an organizational policy for managing cybersecurity risks and making sure that policy is communicated across the organization and enforced. The policy is meant to reflect the organization's own context, strategy, and priorities rather than a one-size-fits-all rule.

Formal definition

GV.PO is a category under the Govern (GV) function of the NIST Cybersecurity Framework 2.0, issued by the U.S. National Institute of Standards and Technology. It addresses the establishment, communication, and enforcement of policy for managing cybersecurity risks, grounded in organizational context, cybersecurity strategy, and priorities. In CSF 2.0, the category comprises subcategories covering the establishment and communication of the cybersecurity risk management policy (GV.PO-01) and its review, update, and communication as the organization and threat environment change (GV.PO-02). As a governance-pillar construct, GV.PO establishes the policy foundation that directs cybersecurity activities; it does not itself specify technical controls, implementation procedures, or tooling, and its precise application depends on the organization's context, sector, and jurisdiction. Note that GV.PO is distinct from similarly themed CSF 1.1 elements, and 'GV.PO-01' denotes a subcategory rather than the category as a whole.

Why it matters

Policy sits at the foundation of cybersecurity governance because it translates an organization's context, strategy, and priorities into an authoritative statement that directs how cybersecurity risks are to be managed. Without an established and communicated policy, cybersecurity activities tend to be inconsistent, discretionary, and difficult to hold accountable. GV.PO addresses this by requiring not only that a policy exist, but that it be communicated across the organization and enforced, so that the direction set by leadership actually shapes day-to-day behavior rather than remaining a document on a shelf.

Equally important is the requirement that policy be maintained over time. GV.PO-02 addresses the review, update, and communication of the cybersecurity risk management policy as the organization and its threat environment change. This matters because a policy grounded in yesterday's context, strategy, and priorities can become misaligned as the business evolves, as new obligations emerge, or as the threat landscape shifts. Treating policy as a living instrument, rather than a one-time artifact, is central to keeping governance responsive.

As the introductory step in a broader security strategy, a policy framework for managing cybersecurity risks sets a formal foundation on which subsequent activities are built. GV.PO is a governance-pillar construct: it establishes the direction and authority for cybersecurity work, but it does not by itself guarantee any security outcome. Its value depends on downstream implementation, and its precise application varies with the organization's sector and jurisdiction.

Who it's relevant to

Governance professionals and executive leadership
Those responsible for setting organizational direction use GV.PO to establish an authoritative cybersecurity risk management policy grounded in the organization's context, strategy, and priorities, and to ensure it is communicated and enforced. Because the category concerns decision rights and direction rather than technical implementation, it is primarily a governance-pillar responsibility.
Compliance officers
Compliance functions rely on established, communicated, and enforced policy as the reference point against which adherence to internal requirements can be assessed. GV.PO helps them confirm that a formal policy foundation exists and is maintained, though the specific external obligations that intersect with it will depend on sector and jurisdiction.
Risk managers
Risk practitioners use the policy established under GV.PO as the authoritative basis for how cybersecurity risks are to be managed across the organization. The category's emphasis on review and update as the organization and threat environment change supports keeping risk management direction aligned with evolving conditions.
Internal auditors and assurance providers
Assurance functions may evaluate whether a cybersecurity risk management policy has been established, communicated, enforced, and kept current, consistent with the GV.PO outcomes. Their role is to provide independent, objective evaluation of these governance activities rather than to author or operate the policy themselves.

Inside GV.PO

Policy (GV.PO)
A Category within the Govern (GV) Function of the NIST Cybersecurity Framework (CSF) 2.0, issued by the National Institute of Standards and Technology. It addresses the establishment, communication, and ongoing maintenance of organizational cybersecurity policy, situating policy as a governance mechanism that directs and constrains the cybersecurity program.
GV.PO-01 (establishment and communication)
A subcategory concerned with organizational cybersecurity policy being established and communicated. It emphasizes that policy should be based on organizational context, cybersecurity strategy, priorities, and stakeholder expectations, and made known to those responsible for acting on it.
GV.PO-02 (review, update, and communication)
A subcategory concerned with cybersecurity policy being reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission. This treats policy as a living instrument rather than a one-time artifact.
Governance orientation
As part of the Govern Function, GV.PO concerns the structures and decision-making that direct the cybersecurity program. It is distinct from operational controls or assurance activities; policy sets direction and expectations rather than performing or independently testing safeguards.

Common questions

Answers to the questions practitioners most commonly ask about GV.PO.

Is "Policies, Processes, and Procedures" an accurate alias for the Policy (GV.PO) category?
No. That phrasing does not correspond to the official name of the Policy (GV.PO) category within the Govern (GV) Function of the NIST Cybersecurity Framework. Language referring to organizational policies, processes, and procedures appeared in different parts of earlier framework structures and should not be treated as an alias for GV.PO. When citing the category, use its designated identifier (GV.PO) and its official name to avoid conflating it with distinct constructs.
Does GV.PO refer only to the single subcategory GV.PO-01?
No. GV.PO-01 is a subcategory nested within the GV.PO category, not the category itself, so treating them as interchangeable is a common error. The Policy (GV.PO) category encompasses more than one subcategory, including provisions addressing the establishment and communication of cybersecurity policy as well as the review and update of that policy. When referencing requirements, distinguish the category-level identifier (GV.PO) from the specific subcategory identifiers beneath it.
How does the Policy (GV.PO) category relate to the broader Govern (GV) Function?
GV.PO is one category within the Govern Function, which addresses how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policy. Within that context, GV.PO focuses specifically on the organizational cybersecurity policy itself. Implementation specifics, tooling, and the drafting of policy content are outside the scope of the category definition, which describes intended outcomes rather than prescribing how to achieve them.
What is the difference between establishing a policy and reviewing or updating it under GV.PO?
Establishing and communicating cybersecurity policy is a distinct outcome from reviewing and updating it; the category treats these as separate subcategory-level concerns. Establishment addresses whether a policy exists and is communicated across the organization, while review and update address whether the policy is maintained over time in response to changes in strategy, requirements, risk, or the operating environment. Organizations commonly assign responsibility for both, since a policy that is established but not periodically revisited can become misaligned with current conditions.
Who is typically responsible for cybersecurity policy under a GV.PO-aligned approach?
Accountability for cybersecurity policy commonly rests with governance bodies and senior management, who set direction and expectations, while operational functions apply and support the policy. This reflects a governance activity rather than an assurance activity: management owns and maintains policy, whereas independent assurance functions may evaluate whether policy exists and is followed. Specific role assignments vary by organization size, sector, and jurisdiction, and the framework does not mandate a particular structure.
How often should cybersecurity policy be reviewed to align with GV.PO expectations?
The framework does not prescribe a fixed review interval. In practice, many organizations review cybersecurity policy on a periodic basis and also on a triggered basis, for example following significant changes in the risk environment, business objectives, regulatory obligations, or after notable incidents. The appropriate cadence typically depends on the organization's risk profile, sector, and applicable requirements, so review frequency should be determined by the organization rather than assumed to be universal.

Common misconceptions

GV.PO contains a single subcategory covering policy establishment.
In CSF 2.0, the Policy Category includes two subcategories: GV.PO-01, addressing establishment and communication of cybersecurity policy, and GV.PO-02, addressing review, update, communication, and enforcement.
'GV.PO-01' is another name for the GV.PO Category.
GV.PO is the Category; GV.PO-01 is one subcategory within it. Referring to a subcategory identifier as if it were the Category conflates two different levels of the CSF structure.
Establishing a cybersecurity policy under GV.PO satisfies the requirement on an ongoing basis.
GV.PO treats policy as something to be maintained. GV.PO-02 addresses periodic review, updating, communication, and enforcement so policy stays aligned with changing requirements, threats, technology, and mission.

Best practices

Ground cybersecurity policy in organizational context, strategy, priorities, and stakeholder expectations rather than adopting generic templates, consistent with GV.PO-01.
Communicate policy to the roles responsible for acting on it, confirming that intended audiences are aware of the direction the policy sets.
Establish a defined cadence and triggers (such as significant changes in threats, technology, requirements, or mission) for reviewing and updating policy, in line with GV.PO-02.
Distinguish the policy itself from the standards, procedures, and controls that implement it, keeping GV.PO focused on governance direction rather than operational execution.
Assign clear ownership for enforcing policy and for maintaining it over time, and record when reviews and updates occur.
Treat GV.PO as governance direction only; coordinate with the assurance functions that independently evaluate whether policy is being followed, without conflating those roles.
Promotional banner for the Pentest Readiness checklist download