Acceptance criteria decide in evaluation whether a risk is acceptable and in treatment whether a proposed treatment is enough or more is needed, and the organisation defines levels of acceptance. In building them it considers: alignment with its general risk acceptance criteria; which management level holds delegated authority to accept; that there can be several thresholds with acceptance authority at different levels; that criteria can rest on likelihood and consequence alone or also weigh the cost of controls against prospective loss; that different classes of risk can have different criteria (risks of legal non-compliance may not be retainable, while contractually required acceptance may be allowed); that criteria can allow future treatment, retaining a risk above threshold for a short time when there is approved commitment to controls within a set period; that criteria derive from risk appetite; and that they can be absolute or conditional. Influencing factors, not exhaustive, are organisational objectives and opportunities, legal and regulatory aspects, operations, technological and financial constraints, processes, supplier relationships and human factors such as privacy. A yes or no test is often not enough: thresholds may be needed for extreme consequences whatever their likelihood, or very high likelihoods whatever the consequence, so criteria ideally consider likelihood and consequence separately and management cost, not only the combined level. A keener appetite means a higher threshold and guards against over-control; criteria can vary with how long a risk will exist; they are reviewed and updated as context changes; and authorised management approves them.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.