APRA CPS 220 Risk Management CPS220-02: Board Responsibility for the Risk Management Framework
The Board is ultimately responsible for the risk management framework and for overseeing its operation by management, and must ensure it sets risk appetite and approves the risk appetite statement and risk management strategy, forms a view of risk culture and drives any changes needed, has senior management monitor and manage all material risks consistently with approved strategy, appetite and policies, has an operational structure that supports effective risk management, has risk taking policies and processes consistent with the strategy and appetite, dedicates sufficient resources to risk management, and recognises the uncertainties, limitations and assumptions in measuring each material risk.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 16 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
NIST-CSF-GV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies