The risk appetite statement must convey at least the degree of risk the institution will accept in pursuit of its strategic objectives and business plan having regard to the interests of depositors or policyholders, for each material risk the maximum level it is willing to operate within expressed as a risk limit based on appetite, profile and capital strength, the process for setting risk tolerances at an appropriate level based on estimated breach impact and likelihood, the process for monitoring compliance with each tolerance and acting on a breach, and the timing and process for reviewing appetite and tolerances.
This control maps to 8 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.