ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.3.4: Defining risk criteria

Guidance: the organization should state how much risk, and of what kinds, it is or is not willing to take in relation to its objectives, and should define criteria for judging the significance of risk and supporting decisions. Risk criteria should align with the framework and be customized to the purpose and scope of the activity; they should express what the organization values, what it aims for and what resources it has, be consistent with its policies and statements on risk, and take account of its obligations and stakeholder views. Criteria should be set at the start of the assessment and, being dynamic, should be reviewed and amended as needed. Setting criteria should consider what kinds of uncertainty, tangible or intangible, can bear on outcomes and objectives; the definition and measurement of likelihood and of consequences, favourable or unfavourable; time-related factors; measurements applied consistently; the method for arriving at a level of risk; the treatment of several risks that combine or follow one another; and the organization's capacity.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 7 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 5 controls

  • 5.5.2 Defining the objectives, scope and criteria for an individual audit
  • 6.3.3 Assigning work to audit team
  • 6.5.1 Preparing audit report
  • 7.2 Determining auditor competence
  • 7.3 Establishing auditor evaluation criteria

ISO/IEC 23894:2023 · 1 control

  • 6.3.4 Defining risk criteria
  • 0036 0036 Determine and document security risk tolerance

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.