APRA CPS 220 Risk Management
RMF

APRA CPS 220 Risk Management CPS220-04: Maintenance of a Risk Management Framework

The institution must maintain a risk management framework that lets it develop and implement strategies, policies, procedures and controls for the different types of material risk and that gives the Board a comprehensive institution wide view of material risks.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 24 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • SPS220-17 Maintenance of a Risk Management Framework
  • SPS220-18 Framework Coverage of All Material Risks

FedRAMP High · 2 controls

  • RA-1 Policy and Procedures
  • RA-3 Risk Assessment

FedRAMP Moderate · 2 controls

  • RA-1 Policy and Procedures
  • RA-3 Risk Assessment

NIST SP 800-161 Rev 1 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • s912A-1d-h s 912A(1)(d) and (h) Have adequate resources and adequate risk management systems

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in RMF

Query this from an agent

The graph holds this control, the 24 it maps to, and the evidence behind each claim, over MCP and REST.