NIST CSF 2.0 · derived mapping target
GV.RR-01Leadership accountability for cyber risk
Make senior leaders visibly accountable for cyber risk and have them champion a culture that is risk-aware, ethical, and always improving. Tone at the top drives everything below.
Mapping at a glance
GV.RR-01Leadership accountability for cyber riskNIST CSF 2.0
GV.RR-01 is covered by 9 Sekit CSF controls. +4 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0004Roles & responsibilities · PolicyRCF-0005Roles & responsibilities · ProcessRCF-0006Roles & responsibilities · TechnicalRCF-0028Security charter · PolicyRCF-0029Security charter · ProcessRCF-0030Security charter · TechnicalRCF-0397Executive briefings · PolicyRCF-0398Executive briefings · ProcessRCF-0399Executive briefings · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Information security policy
The written, leadership-approved document that sets the company's security rules: what is protected, how, and who is responsible.
Security roles and responsibilities
The document or chart showing who owns each aspect of security in the company (e.g. a security org chart or a RACI matrix).
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves GV.RR-01?”
Also via MCP, free with account