SekitCrosswalk
NIST CSF 2.0 · derived mapping target

GV.PO-01Cybersecurity policy established

Write a cybersecurity policy grounded in your context, strategy, and priorities, then communicate and enforce it. A policy nobody knows about protects nothing.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
From the Sekit evidence catalog

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves GV.PO-01?”
Also via MCP, free with account