Guidance: risk analysis builds an understanding of the nature and characteristics of a risk, including its level where appropriate, by considering in detail uncertainties, risk sources, events, scenarios, consequences, likelihood, controls and how effective they are; one event can have several causes and consequences and touch several objectives. Analysis can be done at different depths depending on its purpose, the information available and its reliability, and the resources to hand, and can be qualitative, quantitative or both. It should consider how likely events and consequences are, what the consequences are and how large, complexity and interconnection, time-related factors and volatility, how well current controls work, and sensitivity and confidence levels. Diverging opinions, biases, perceptions and judgements influence analysis, as do the quality of information, the assumptions and exclusions made and the limits of the techniques; these influences should be weighed, written down and passed to decision makers. Events of great uncertainty with severe consequences are hard to quantify and a combination of techniques usually gives more insight. Analysis feeds evaluation, the decision on whether and how to treat a risk, and the choice of treatment strategy.
This control maps to 10 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.