The organisation uses its organisational risk assessment process where one exists, or defines an information security one. Assessment lets risk owners prioritise risks for treatment, mainly on consequence and likelihood or other set criteria. The assessment's context is fixed, with its scope and purpose and the internal and external issues bearing on it. It comprises identification (finding, recognising and describing risks, 7.2), analysis (understanding the kinds of risk and setting the level, considering causes and sources, the likelihood of an event, the likelihood that it has consequences and how severe they are, 7.3) and evaluation (comparing analysis with criteria to judge acceptability and prioritise for treatment, 7.4). The process rests on methods (6.5) and tools detailed enough for consistent, valid and reproducible results whose outcomes can be compared, for example to see whether a level has risen or fallen, and it is aligned with organisational risk management so information security risks can be set against other risks. ISO/IEC 27001 prescribes no approach, but the two main ones, event-based and asset-based, are discussed in 7.2.1.
This control maps to 5 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.