Assessment and treatment are refreshed regularly and whenever things change, organised in two cycles. The strategic cycle responds to shifts in the organisation's overall context (its business assets, the threats and sources of risk it faces, the objectives it targets, and what security events would cost it) and can prompt a broad update of assessments and treatments or wholly new assessments; it runs over longer intervals or on major change. The operational cycle uses those elements, or changed criteria, to review and update the scenarios of individual assessments together with their treatment, over shorter intervals set by the detailed risks involved. The strategic cycle concerns the environment in which objectives are pursued, the operational cycle every assessment within the risk management context, and either can contain many assessments with differing context and scope.
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.