NIST CSF 2.0 · derived mapping target
GV.PO-02Cybersecurity policy maintained
Review and refresh the policy as threats, technology, requirements, and the business change, and re-communicate updates. A stale policy quietly stops reflecting reality.
Mapping at a glance
GV.PO-02Cybersecurity policy maintainedNIST CSF 2.0
GV.PO-02 is covered by 18 Sekit CSF controls. +13 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0001Policy management · PolicyRCF-0002Policy management · ProcessRCF-0003Policy management · TechnicalRCF-0013Exception management · PolicyRCF-0014Exception management · ProcessRCF-0015Exception management · TechnicalRCF-0358Consent & preference mgmt · PolicyRCF-0359Consent & preference mgmt · ProcessRCF-0360Consent & preference mgmt · TechnicalRCF-0361Data subject rights · PolicyRCF-0362Data subject rights · ProcessRCF-0363Data subject rights · TechnicalRCF-0364Privacy by design · PolicyRCF-0365Privacy by design · ProcessRCF-0366Privacy by design · TechnicalRCF-0367Privacy notices · PolicyRCF-0368Privacy notices · ProcessRCF-0369Privacy notices · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves GV.PO-02?”
Also via MCP, free with account