ISO 31000:2018
Framework – ISO 31000:2018

ISO 31000:2018 5.5: Implementation

Guidance: the organization should implement the framework by developing a plan with time and resources attached; by identifying where, when and how the different kinds of decision are taken in the organization, and who takes them; by changing the decision-making processes where that is needed; and by making sure its arrangements for managing risk are understood and practised. Implementation succeeds when stakeholders are engaged and aware, which lets the organization address uncertainty explicitly when it decides and pick up new uncertainty as it arises. A framework designed and implemented properly makes the risk management process part of every activity including decision-making and captures shifts in the internal and external context.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 28 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 17 controls

  • 5.4 Establishing the audit programme
  • 5.5 Implementing audit programme
  • 5.5.3 Selecting and determining audit methods
  • 5.5.4 Selecting audit team members
  • 5.6 Monitoring audit programme
  • 6.3 Preparing audit activities
  • 6.3.3 Assigning work to audit team
  • 6.4 Conducting audit activities
  • 6.4.3 Conducting opening meeting
  • 6.4.8 Generating audit findings
  • 6.4.9 Determining audit conclusions
  • 6.5.1 Preparing audit report
  • 6.5.2 Distributing audit report
  • 6.7 Conducting audit follow-up
  • 7.2 Determining auditor competence
  • 7.2.3 Knowledge and skills
  • 7.2.4 Achieving auditor competence

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • BR-OF-A1 Implementation and scope of Open Finance

ISO 10005:2005 · 1 control

  • 6.2 Implementation of the quality plan

ISO 14004:2016 · 1 control

  • 10.3.2 Implementation of continual improvement

ISO 22301:2019 · 1 control

  • 8.3.5 Implementation of solutions
  • 27557-5.4 Implementation and evaluation

NIST SP 800-128 · 1 control

NIST SP 800-160 · 1 control

  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Framework – ISO 31000:2018

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.