Guidance: the organization should state how much risk, and of what kinds, it is or is not willing to take in relation to its objectives, and should define criteria for judging the significance of risk and supporting decisions. Risk criteria should align with the framework and be customized to the purpose and scope of the activity; they should express what the organization values, what it aims for and what resources it has, be consistent with its policies and statements on risk, and take account of its obligations and stakeholder views. Criteria should be set at the start of the assessment and, being dynamic, should be reviewed and amended as needed. Setting criteria should consider what kinds of uncertainty, tangible or intangible, can bear on outcomes and objectives; the definition and measurement of likelihood and of consequences, favourable or unfavourable; time-related factors; measurements applied consistently; the method for arriving at a level of risk; the treatment of several risks that combine or follow one another; and the organization's capacity.
This control maps to 7 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.