The enterprise builds a well-founded picture of the I&T risk it actually faces, to inform risk decisions. The scope of the analysis is set with regard to all risk factors and to how critical assets are. I&T risk scenarios, loss exposures and reputational scenarios, including threats that compound, cascade or coincide, are developed and refreshed regularly. For each scenario the likely frequency and size of loss or gain are estimated, allowing for risk factors and the controls known to be in place. Current exposure is set against appetite and tolerance to find risk that is unacceptable or raised. Responses are proposed for any risk outside appetite and tolerance. High-level requirements are specified for the projects or programmes that will deliver the responses and for the key controls they require. Before the analysis and the business impact analysis are relied on for decisions they are validated, confirming they fit enterprise requirements and that estimates were properly calibrated. The costs and benefits of the response options (avoid, reduce, transfer or share, accept, exploit) are analysed to confirm which response is best.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.