APRA CPS 220 Risk Management
Risk Identification

APRA CPS 220 Risk Management CPS220-P33: Risks Arising from Strategic Objectives and the Business Plan

The institution must identify and consider the material risks associated with its strategic objectives and business plan and must explicitly manage those risks through the risk management framework, including how changing those plans affects its risk profile.

What else in your programme already covers this

This control maps to 11 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PM-11 Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and
  • NIST800-RA-3 Risk assessment

SOC 2 · 2 controls

  • SOC2-CC3.1 COSO principle 6: Specifies objectives to identify and assess risks
  • SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls

CMMC 2.0 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Risk Identification

Query this from an agent

The graph holds this control, the 11 it maps to, and the evidence behind each claim, over MCP and REST.