Leveraging related ISMS processes – ISO 27005:2022
ISO 27005:2022 10.2: Leadership and commitment
Input: assessment or treatment results needing approval or endorsement. Action: the appropriate management level reviews the results and decides on, or endorses, what happens next. Trigger: 27001 requires suitable management involvement in all risk-related activities. Output: risk decisions or endorsements. Accountability for managing risk rests with top management, which leads and drives assessments, including allocating the resources risk management needs, assigning authority, responsibility and accountability for it at the right levels, and communicating with the relevant interested parties.
This control maps to 34 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.