The risk management framework must include at least the risk appetite statement, the risk management strategy, a designated risk management function meeting the required criteria, all risk management policies, procedures and controls to identify, assess, monitor, report on, mitigate and manage each material risk, clearly defined and documented roles, responsibilities and formal reporting structures for managing material risks throughout business operations, a management information system adequate in normal and stressed conditions for measuring, assessing and reporting all material risks, and a review process ensuring the framework remains effective.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.