NIST SP 800-53 Rev 5
PM - Program Management

NIST SP 800-53 Rev 5 PM-28: Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and

Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and

What else in your programme already covers this

This control maps to 80 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

ISO 22301:2019 · 6 controls

  • 4.1 Understanding the organization and its context
  • 5.1 Leadership and commitment
  • 6.1.1 Determining risks and opportunities
  • 8.2 Business impact analysis and risk assessment
  • 8.2.1 General
  • 8.2.3 Risk assessment
  • CPS220-02 Board Responsibility for the Risk Management Framework
  • CPS220-06 Risk Appetite Statement
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P28 Minimum Contents of the Risk Appetite Statement

FedRAMP High · 5 controls

  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • PL-10 Baseline Selection. Select a control baseline for the system
  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • SR-2 Supply Chain Risk Management Plan (SR-2)

ISO/IEC 42001:2023 · 5 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 6.1.1 General
  • 6.1.2 Risk assessment
  • 8.2 AI risk assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • PL-10 Baseline Selection. Select a control baseline for the system
  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • PL-10 Baseline Selection. Select a control baseline for the system
  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • PL-10 Baseline Selection. Select a control baseline for the system
  • RA-3 Risk Assessment
  • RA-7 Risk Response
  • SR-2 Supply Chain Risk Management Plan (SR-2)

FedRAMP Moderate · 4 controls

  • CA-7(4) Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
  • PL-10 Baseline Selection. Select a control baseline for the system
  • RA-3 Risk Assessment
  • SR-2 Supply Chain Risk Management Plan (SR-2)

HIPAA Security Rule · 4 controls

ISO 27002:2022 · 4 controls

  • 5.1 Policies for information security
  • 5.2 Information security roles and responsibilities
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.7 Threat intelligence

ISO 27701:2019 · 4 controls

  • 5.2.1 Understanding the organization and its context
  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment

NIST SP 800-66 Rev 2 · 4 controls

SOC 2 · 2 controls

  • SOC2-CC3.1 COSO principle 6: Specifies objectives to identify and assess risks
  • SOC2-CC3.2 COSO principle 7: Identifies risks and analyzes to determine how managed
  • CPS230-15 Operational Risk Elements of the Risk Management Framework

C5 (Germany) · 1 control

EU AI Act · 1 control

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

PCI DSS 4.0 · 1 control

  • 12.3.2 TRA for customized approach

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PM - Program Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 PM-28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 300 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.