Every stakeholder who needs it receives timely information on where I&T-related exposures and opportunities currently stand, so that they can respond appropriately. Results of risk analysis go to the stakeholders affected in wording and formats that help them decide, including where possible probabilities, ranges of loss or gain and confidence levels, so risk can be weighed against return. Decision makers understand the worst-case and most-likely scenarios, loss exposures and significant reputational, legal and regulatory factors. The current risk profile is reported to all stakeholders, covering how effective the risk process and controls are, the gaps, inconsistencies and redundancies found, the status of remediation, and how all of these affect the profile. Where risk and risk capacity are balanced, the enterprise looks periodically for chances to take on more risk in pursuit of growth and return. Findings from independent third-party assessments, internal audit and quality assurance reviews are examined and folded into the profile.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.