APRA CPS 220 Risk Management
RMF

APRA CPS 220 Risk Management CPS220-P22: Framework Structure for Managing Each Material Risk

The risk management framework must provide a structure for identifying and managing each material risk so the institution is prudently and soundly managed, having regard to the size, business mix and complexity of its operations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

HIPAA Security Rule · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • 12 Para 12 Identify, assess and manage operational risk

C5 (Germany) · 1 control

  • C5-OIS-07 Application of the Risk Management Policy

CMMC 2.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in RMF

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.