Guidance: the organization should set out what its risk management activities cover. Because the process can run at strategic, operational, programme, project or other levels, it should be clear which scope is under consideration, which objectives are relevant and how they align with the organization's objectives. Planning the approach should consider the objectives and decisions to be made; the outcomes expected from the steps; time, location and specific inclusions and exclusions; the assessment tools and techniques that fit; the resources needed, the responsibilities and the records to keep; and the links to other projects, processes and activities.
This control maps to 10 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.