GV.RR-04 Cybersecurity is included in human resources practices
Cybersecurity is included in human resources practices. Control from NIST Cybersecurity Framework 2.0 framework, domain: GV - Govern.
5
artefacts
1
held by a system
0
at each review
hard
to go live
HR system / LMS
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Joiner mover leaver workflow with security gates · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- HR policies covering hiring, transfer, and termination security · HR system / LMS
- Background screening standards by role sensitivity · Policy repository / GRC workspace
- Disciplinary procedure for security violations · HR system / LMS
- HR audit findings on security integration · HR system / LMS
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Background screening not refreshed for role changes
- Leaver process delayed beyond same day for cloud assets
- Disciplinary outcomes not measured
- Contractor lifecycle ignored
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies · GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders