CSF 2.0 outcome: risk responses are chosen, prioritized, planned, tracked and communicated. Priority High. N1: risk responses are needed to prevent future incidents and stop existing ones recurring. R1: policies, processes and procedures should give guidance, such as criteria, for deciding the appropriate risk response in different situations. N2: the four responses are accept, mitigate (remove vulnerabilities or add controls), transfer (share consequences with another party) and avoid (remove the attack surface). N3: see NIST IR 8286. N4: see the ID.RA notes.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.