C5 (Germany)
C5: Organisation of Information Security

C5 (Germany) C5-OIS-07: Application of the Risk Management Policy

Run the risk handling process as needed and at least once a year, addressing mixed customer protection needs, weaknesses in the separation of shared resources, attacks through publicly reachable interfaces, unavoidable duty conflicts and subservice dependencies, with risk owners reviewing treatment and residual risk annually.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 57 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P18 Integration with the Risk Management Framework and Recovery Planning
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-17 Enterprise Technology Risk Assessment
  • CFTC-SS-2 Enterprise Risk Management and Governance Category

ISO 22301:2019 · 3 controls

  • 6.1.1 Determining risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment

SOC 2 · 3 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • CBPR-PR-28 Safeguards proportional to risk
  • CBPR-PR-34 Risk assessments and third party certifications
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-P17 Active Maintenance of Capability Against Change
  • SEC01-BP03 Identify and validate control objectives
  • SEC01-BP07 Identify threats and prioritize mitigations using a threat model

FedRAMP Moderate · 2 controls

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 5.6.2 Information security risk assessment
  • 7.2.5 Privacy impact assessment

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • ASBv3-GS-5 Define and implement security posture management strategy

CMMC 2.0 · 1 control

DORA · 1 control

FedRAMP High · 1 control

  • RA-3 Risk Assessment

GDPR · 1 control

ISO/IEC 23894:2023 · 1 control

  • 23894-5.4.2 AI Risk Management Policy
  • 5.4 Application of risk management

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

NIST SP 800-172 · 1 control

  • 3.11.1e Threat-Aware Risk Assessment

NIST SP 800-218 · 1 control

PCI DSS 4.0 · 1 control

  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in C5: Organisation of Information Security

You are reading one control. How much of C5 (Germany) have you already done?

C5 (Germany) C5-OIS-07 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of C5 (Germany) your existing evidence covers. Hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and 95 of 121 C5 (Germany) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.