https://www.gao.gov/products/GAO-22-105103 - February 2022
More guidance for adopting frameworks like NIST.
I would suggest reading the recent GAO report 'GAO-22-105103' in concert with GAO-19-332. Both make certain assertions that are even more significant given the USA's admission of increasing cyber risks, or wait until resources you are responsible have been compromised, then use these documents to justify the cost of fixing issues.
Your choice.