The organisation develops, documents and disseminates to defined personnel or roles a risk assessment policy at the selected organisation, business process and, or, system level that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organisational entities and compliance and is consistent with applicable laws, Orders in Council, jurisprudence, directives, regulations, policies, standards and guidelines, together with procedures to implement the policy and the associated risk assessment controls; designates an official to manage the policy and procedures; and reviews and updates the policy and the procedures at a set frequency and after defined events. The GC discussion ties risk assessment policy to the privacy impact assessment process established by the head of the institution. 1 enhancement, including the Canada-specific (400) Privacy impact assessments.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.