- Scoped Organizational ProfileFoundational
- What the profile covers, stated plainly. Without it, nothing later is comparable.
- Risk appetite and tolerance statementFoundational
- A GOVERN outcome, and the document that makes “accept this risk” a decision rather than a shrug.
- Roles, responsibilities and authoritiesFoundational
- Who decides, who executes, and who is accountable to whom for cybersecurity risk.
- Asset and data inventoryFoundational
- Hardware, software, services, data and the flows between them. The dependency for most of IDENTIFY and PROTECT.
- Policy set with review datesRecurring
- Approved, communicated, and reviewed on a stated cycle rather than when someone remembers.
- Supplier risk criteria and assessmentsRecurring
- The supply chain Category is the largest in GOVERN. Most first profiles have almost nothing here.
- Monitoring coverage mapRecurring
- What is logged, what is monitored, and which assets nobody is watching at all.
- Vulnerability and remediation recordsRecurring
- The cadence, and proof the cadence happened, with exceptions recorded.
- Incident response plan and exercise recordsEvent-driven
- A plan with named roles, plus the date it was last exercised and what the exercise changed.
- Recovery plan and restoration test resultsEvent-driven
- A real restore with a date and a result. RECOVER is where untested assumptions live.
- Awareness and training completionTime-bound
- By person and date. The artefact most likely to have quietly expired.
- Oversight reporting to the boardTime-bound
- GOVERN expects senior oversight. Minutes and a reporting pack are how you evidence it.