The organization documents objectives and targets for managing risk so that disruptive incidents are prevented, avoided, contained and mitigated, and so that it can respond and recover when one occurs, stating the internal and external expectations, across the organization and its supply chain, that are critical to its mission, product and service delivery and operations. Objectives follow from the policy and the risk assessment and commit to: reducing risk by lowering likelihood and severity; raising resilience through adaptive, proactive and reactive approaches that account for financial, operational and business needs including the supply chain; meeting legal and other requirements; and continual improvement. In setting and revising them the organization weighs legal requirements, significant risks, technology options, financial, operational and business needs, and the views of stakeholders. Targets are measured qualitatively or quantitatively, derived from the objectives and: detailed enough; in line with the risk assessment and recovery time objectives; specific, measurable, achievable, relevant and time-bound where practical; made known to staff and third parties such as contractors and supply chain partners so they know their part; and reviewed and adjusted periodically.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.