NIST Cybersecurity Framework 1.1 ID.RM-1: ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
Risk management processes are established, managed, and agreed to by organizational stakeholders. IDENTIFY (ID) Function, Risk Management Strategy (ID.RM) Category. Outcome in the Framework Core of Version 1.1; withdrawn in CSF 2.0 (incorporated into GV.RM-01, GV.RM-06, GV.RR-03).
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
NIST-CSF-GV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies