The process of Figure 1 follows the generic ISO 31000 model and can loop through assessment and treatment. Each pass of the assessment can go deeper, which balances the effort of finding controls against assessing risks properly. Context establishment gathers the internal and external context for the risk management or for a given assessment. At the first decision point, if the assessment yields enough to settle how risks can be brought within acceptable bounds, the organisation moves on to treatment; if not it runs another pass, perhaps with a changed scope, more specialist input or other ways of getting the missing information. Treatment itself loops: formulate and choose options, plan and implement, check how effective the treatment was, decide whether what remains is acceptable, and treat further if it is not. If residual risk is still unacceptable (the second decision point), the organisation looks for more treatment or reassesses in whole or part, using what it has learned about threats and vulnerabilities. Clauses 6, 7, 8 and 10 cover context, assessment, treatment and the supporting ISMS activities.
This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.