The governing body keeps examining and evaluating how risk bears on the use of I&T now and in future, considers whether the enterprise's appetite for risk is suitable, and sees that risk to enterprise value arising from I&T is identified and managed. It understands the organisation and the context of its I&T risk; sets the risk appetite (how much I&T-related risk the enterprise is prepared to accept while pursuing its objectives) and the tolerance levels, which are deviations from that appetite acceptable for a limited time; checks that the I&T risk strategy fits the enterprise risk strategy and that the appetite stays below the enterprise's risk capacity; weighs I&T risk factors before strategic decisions are taken so that risk forms part of how decisions are made; judges risk management activities against how much I&T-related loss the enterprise can bear and how much its leadership will tolerate; and attracts and retains the people and skills that managing I&T risk requires.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.