16 CFR 314.4(b) risk assessment. REQUIREMENT: financial institution must conduct a WRITTEN RISK ASSESSMENT to identify reasonably foreseeable internal + external risks to the security + confidentiality + integrity of customer information that could result in unauthorized disclosure + misuse + alteration + destruction + or other compromise. RISK ASSESSMENT CONTENTS (314.4(b)(1-4)): (1) CRITERIA for the evaluation + categorization of identified security risks or threats facing the institution; (2) CRITERIA for the assessment of confidentiality + integrity + availability of the institution information systems + customer information including the adequacy of existing controls in the context of identified risks or threats; (3) REQUIREMENTS that the safeguards (the 9 elements at 314.4(c) + 314.4(d-j)) be assessed in light of the risk assessment + adjusted accordingly. FREQUENCY: at least every ANNUAL year + after material changes to operations or services + after security events + after relevant regulatory developments. METHODOLOGY: typically aligned with NIST SP 800-30 + ISO 31000 + COSO ERM + integrated with enterprise risk management.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.