NIST Cybersecurity Framework 1.0 ID.RM-2: ID.RM-2: Organizational risk tolerance is determined and clearly expressed
Organizational risk tolerance is determined and clearly expressed. IDENTIFY (ID) Function, Risk Management Strategy (ID.RM) Category. Outcome in the Framework Core of Version 1.0; unchanged in Version 1.1.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.