16 CFR 314.4(b) risk assessment. REQUIREMENT: financial institution must conduct a WRITTEN RISK ASSESSMENT to identify reasonably foreseeable internal + external risks to the security + confidentiality + integrity of customer information that could result in unauthorized disclosure + misuse + alteration + destruction + or other compromise. RISK ASSESSMENT CONTENTS (314.4(b)(1-4)): (1) CRITERIA for the evaluation + categorization of identified security risks or threats facing the institution; (2) CRITERIA for the assessment of confidentiality + integrity + availability of the institution information systems + customer information including the adequacy of existing controls in the context of identified risks or threats; (3) REQUIREMENTS that the safeguards (the 9 elements at 314.4(c) + 314.4(d-j)) be assessed in light of the risk assessment + adjusted accordingly. FREQUENCY: at least every ANNUAL year + after material changes to operations or services + after security events + after relevant regulatory developments. METHODOLOGY: typically aligned with NIST SP 800-30 + ISO 31000 + COSO ERM + integrated with enterprise risk management.
This control maps to 91 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.