The organization should keep a formal documented process for treating risk and choosing countermeasures that considers: removing the source of risk where possible; avoiding the risk by pausing the activity that creates it; making a disruptive event less likely or less damaging, or ruling it out; removing or softening harmful consequences; sharing or transferring risk to others, insurance included; spreading risk across assets and functions; and keeping risk through an informed decision. Top management should weigh the costs and benefits of removing, reducing or keeping risk; keep reviewing treatments and countermeasures as outside conditions shift (new legal, regulatory and other requirements among them) and as the organization itself changes (policy and facilities, information management systems, what it does and supplies, and its supply chain); and keep communication and consultation going between internal and external stakeholders.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.