The governing body directs that risk management practices be put in place so that there is reasonable confidence that I&T risk is managed appropriately and that the I&T risk actually faced stays within the appetite the board has set. The I&T risk strategy is translated into, and built into, risk management practices and operations. Plans for communicating about risk at every level are developed. Mechanisms are put in place to react fast when risk changes and to report it at once to the right management level, following agreed escalation principles that say what is reported, when, where and in what way. Anyone may raise risks, opportunities, issues and concerns with the right party whenever they arise; risk is handled under the policies and procedures the enterprise has published, and passed up to those who decide. The main goals and metrics for governing and managing risk, and how they are to be captured and reported, are identified and approved.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.