Identify and classify hazards and RAM equivalents, select risk acceptance principles, define and apply risk acceptance criteria, assess risks and establish on-going risk management. Risk assessment per 6.3 covers the system definition too; risk analysis (qualitative, quantitative or hybrid) identifies undesired events leading to loss, their causes, the control measures in place, in explicit risk estimation the frequencies and consequences and where reduction is needed, the additional measures required to meet the acceptance criteria or legal requirements, and full documentary evidence of methods, assumptions, data and judgements; safety targets by frequency refer to the single instance of a function or system, not the fleet, with multiple-instance consequences covered by separate scenarios. All reasonably foreseeable hazards and RAM equivalents are systematically identified across normal, fault and emergency operation, foreseeable misuse, interfaces, functionality, configuration parameters, operation, maintenance and support, disposal, human factors, occupational health, and the mechanical, electrical and natural environment; their relationships to consequences are defined; hazards are classified at least into broadly acceptable (registered in the hazard log without further analysis) and not; the risk acceptance principle is selected and, for explicit risk estimation, criteria defined; each risk is evaluated against the criteria. Any analysis states its limits, assumptions, confidence limits of data, and methods. Deliverables: risk assessment, hazard log, updated safety and RAM plans, an ISA plan if appropriate.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.