APRA CPS 220 Risk Management CPS220-P28: Minimum Contents of the Risk Appetite Statement
The risk appetite statement must convey at least the degree of risk the institution will accept in pursuit of its strategic objectives and business plan having regard to the interests of depositors or policyholders, for each material risk the maximum level it is willing to operate within expressed as a risk limit based on appetite, profile and capital strength, the process for setting risk tolerances at an appropriate level based on estimated breach impact and likelihood, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.
What else in your programme already covers this
This control maps to 8 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
NIST800-PM-28 Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and
NIST800-PM-6 Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance
NIST800-PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk