TISAX - Trusted Information Security Assessment Exchange
Information Security Management

TISAX - Trusted Information Security Assessment Exchange TISAX-ISM-02: Risk Management

Implement a systematic approach to information security risk management including asset identification, threat and vulnerability analysis, risk evaluation, and treatment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 110 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-16 Due diligence and onboarding
  • PCI-P2PE-18 Ongoing monitoring and assessment
  • PCI-P2PE-19 Concentration risk management

PCI PIN Security · 3 controls

  • PCI-PIN-16 Due diligence and onboarding
  • PCI-PIN-18 Ongoing monitoring and assessment
  • PCI-PIN-19 Concentration risk management

PCI SSF · 3 controls

  • PCI-SSF-03 Risk appetite and tolerance for IT risk
  • PCI-SSF-16 Due diligence and onboarding
  • PCI-SSF-17 Contractual security requirements

SASB Standards · 3 controls

  • SASB-LG-2 Systemic Risk Management
  • SASB-LG-3 Critical Incident Risk Management
  • SASB-LG-5 Systemic Risk Management
  • SOC-CY-DC1 Nature of Business and Operations
  • SOC-CY-DC3 Cybersecurity Risk Management Objectives
  • SOC-CY-DC4 Governance Structure
  • SOCI-S30AC Obligation to adopt a CIRMP
  • SOCI-S30AD Compliance with CIRMP
  • SOCI-S30AE Annual review of CIRMP

Solvency II · 3 controls

  • SII-P2-11 Remuneration Policy
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • SPS220-28 Annual Board Risk Management Declaration
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • CJIS-19 Supply Chain Risk Management
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

NIST SP 1800-32 · 1 control

  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • TSSR-SEC-3 National Security Risk Management
  • CRM-3 Risk Management Framework
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Information Security Management

Query this from an agent

The graph holds this control, the 110 it maps to, and the evidence behind each claim, over MCP and REST.