The organization sets up and keeps a risk assessment process that: identifies risks from intentional, unintentional and natural hazards and threats with direct or indirect effect on its activities, operations, functions, supply chain, human, intangible and physical assets, the natural environment and stakeholders; analyses risk systematically (likelihood, vulnerability, criticality of impact, consequences); picks out risks with significant effect on activities, functions, goods, services, supply chain, stakeholder relations and the environment; and evaluates and prioritises risk controls and treatment with their costs. It also: keeps this information documented, current and confidential where needed; reviews at set intervals the scope, the policy, the risk assessment and whether the context factors still hold; ensures priority risks shape the resilience system; reassesses when the context, operating environment, procedures, functions, services, partnerships or supply chain change; sets criteria for judging risk that reflect its values, objectives and resources; sets criteria for maximum acceptable downtime, recovery time objectives and acceptable loss for its goods, services, functions and supply chain; sets priority recovery times across the organization and the chain; and weighs the direct and indirect costs and benefits of risk reduction and resilience options. Annex B asks for a formal documented method to ISO 31000:2009 that covers threats, criticality, vulnerability, likelihood, consequence and impact analysis, dependencies in both directions along the chain, data and telecommunications integrity, and impact costs to people, finances, image, the community and the environment.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.