South Korea ISMS-P
Management System

South Korea ISMS-P ISMSP-MS-02: Risk Management

Establish and implement a risk management process including asset identification, threat and vulnerability assessment, risk analysis, and risk treatment plan development.

What else in your programme already covers this

This control maps to 348 controls across 158 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27005 · 6 controls

ISO 31000 · 6 controls

ISO/IEC 23894:2023 · 6 controls

NIST SP 800-30 · 6 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-53 Rev 5 · 6 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

Japan AI Guidelines · 4 controls

NIST SP 800-37 · 4 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

SASB Standards · 4 controls

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 29134:2023 · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

  • 3.11 Encrypt Sensitive Data at Rest
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management

NIST SP 800-39 · 3 controls

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

Solvency II · 3 controls

  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • SPS220-28 Annual Board Risk Management Declaration
  • P1-S1 Advance Electronic Information
  • P1-S2 Risk-Management Systems
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO/IEC 27014:2020 · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-8 Supply Chain Risk Management (CIP-013)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures

GDPR · 1 control

ISO 13485 · 1 control

  • ISO13485-06 Security management process and risk analysis

ISO 22000 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27799 · 1 control

  • ISO27799-06 Security management process and risk analysis

ISO 45001 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

LGPD · 1 control

Liechtenstein DPA · 1 control

MARS-E · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework

NIST SP 800-190 · 1 control

  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures
  • RA-1 Policy and Procedures

NIST SP 800-66 · 1 control

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices

PDPA Singapore · 1 control

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 1 control

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management

POPIA · 1 control

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration

Saudi Arabia PDPL · 1 control

  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-3 Self-Assessment and Board Engagement
  • s.54(5) Statement Content Requirements
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Management System

Query this from an agent

The graph holds this control, the 348 it maps to, and the evidence behind each claim, over MCP and REST.