Communicate risk per NIST SP 800-30 Rev 1 Section 3.3 Step 7 (Communicating and Sharing Risk Assessment Information). Communication must address (a) decision makers (system owner, mission owner, authorising official, Risk Executive Function, board) with appropriate tier-specific framing, (b) stakeholders inside and outside the assessment scope (shared service providers, mission partners, customers, regulators), (c) external sharing (CISA, sector ISACs, regulator reporting where required by statute or contract). Communication artefacts must include the risk assessment report, executive summary, risk register, prioritised risk list, recommended risk responses, residual uncertainty statement, and the next-assessment trigger conditions. Adopt a standard report template (per Appendix K Risk Assessment Reports) for consistency across assessments and tiers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.