Input: all risk information from risk management. Action: monitor, review and improve the risk management process as needed. Trigger: the wish to improve and mature from lessons learned. Output: a process that stays relevant to business objectives, or an updated one. Ongoing review keeps context, assessment and treatment outcomes and management plans suited to circumstances; agreed improvements or actions to improve compliance with the process are notified to responsible managers, who are assured no risk is missed or understated and that decisions give a realistic understanding and ability to respond. Change management feeds the risk process continually so changes to information systems that could modify risk are picked up, even altering assessment activities. The criteria used to measure risk are verified regularly against business objectives, strategies, policies and changes in business context, covering legal and environmental context, competition, the assessment approach, asset values and categories, consequence, likelihood, evaluation and acceptance criteria, the resources needed and the total cost of ownership; assessment and treatment resources remain available to review risk, address new threats and vulnerabilities and advise management. Monitoring may change approach, method or tools according to risk maturity, changes found, the assessment iteration, the purpose of risk management (such as continuity, incident resilience or compliance) and its object (organisation, business unit, process, technical implementation, application, internet connection); the cycles of 5.2 apply.
This control maps to 35 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.