The organization chooses and builds control activities that help bring risks to its objectives down to acceptable levels. Points of focus (6). Link to risk assessment: control activities make sure the risk responses chosen are actually carried out. Entity-specific factors: the environment, the complexity, nature and scope of operations, and the organization's particular characteristics influence which controls are chosen. Relevant processes: management decides which business processes need control activities. Mix of types: controls combine manual and automated, and preventive and detective, approaches. Level of application: control activities are considered at the different levels of the entity. Segregation of duties: incompatible duties are separated, and where that cannot practicably be done, other controls are chosen instead. Approaches the framework suggests for external financial reporting: linking risks to controls with matrices, workshops or a list of control activities; putting in place or monitoring controls where work is outsourced to a third party; weighing the different kinds of control activity; weighing alternatives where duties cannot be segregated; identifying functions that are incompatible.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.