← NIST CSF 2.0 in plain English

GV.PO-01

Govern / Policy

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.

Think of it likePosting the house rules on the fridge so everyone has actually seen them, instead of keeping them in your head.

In plain English

The family writes down its safety rules, makes sure everyone has read them, and expects them to be followed.

Related CIS safeguards (unofficial mapping)