The organization identifies the risks to its objectives throughout the entity and analyses them to decide how they should be managed. Points of focus (5). Levels: risks are identified and assessed at every level relevant to the objectives, whether entity, subsidiary, division, operating unit or function. Internal and external factors: risk identification takes into account factors from inside and outside and how they affect objectives. Management involvement: the mechanisms for assessing risk involve the appropriate levels of management. Significance: risks that have been identified are analysed, including an estimate of how significant they could be. Response: the assessment considers how each risk should be handled, whether by acceptance, avoidance, reduction or sharing. Approaches the framework suggests for external financial reporting: following a process for identifying risk; assessing risks to the significant accounts in the financial statements; meeting staff across the entity; assessing how likely and how significant identified risks are; weighing factors from inside and outside; evaluating the responses to risk.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.