NIST SP 800-53 Rev 5 MODERATE RA-1: Policy and Procedures
Develop and review risk assessment policy at least annually.
What else in your programme already covers this
This control maps to 162 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
12.1.1 An overall information security policy is: • Established. • Published. • Maintained. • Disseminated to all relevant personnel, as well as to relevant vendors and business partners
12.1.2 The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment