risk-management Controls
12 controls across 3 frameworks.
HIPAA
NIST CSF
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Govern / Oversight
Risk management objectives are established and agreed to by organizational stakeholders
Govern / Risk Management Strategy
Risk appetite and risk tolerance statements are established, communicated, and maintained
Govern / Risk Management Strategy
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Govern / Risk Management Strategy
Strategic direction that describes appropriate risk response options is established and communicated
Govern / Risk Management Strategy
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
Govern / Risk Management Strategy
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Govern / Risk Management Strategy
Strategic opportunities (positive risks) are characterized and included in organizational cybersecurity risk discussions
Govern / Risk Management Strategy
Supply chain risk management is integrated into enterprise risk management processes
Govern / Cybersecurity Supply Chain Risk Management
Changes and exceptions are managed, assessed for risk impact, and tracked
Identify / Risk Assessment