Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on a regular basis. Document risk treatment decisions including accept + mitigate + transfer + avoid. Update risk register on at least an annual basis or upon material change in operations or threat landscape.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.