PM-28 Risk Framing

Program Management

Privacy New in Rev 5

Description

a. Identify and document: 1. Assumptions affecting risk assessments, risk responses, and risk monitoring; 2. Constraints affecting risk assessments, risk responses, and risk monitoring; 3. Priorities and trade-offs considered by the organization for managing risk; and 4. Organizational risk tolerance; b. Distribute the results of risk framing activities to [Assignment: organization-defined personnel]; and c. Review and update risk framing considerations [Assignment: organization-defined frequency].

Supplemental Guidance

Risk framing is most effective when conducted at the organization level and in consultation with stakeholders throughout the organization including mission, business, and system owners. Risk framing results are shared with organizational personnel, including mission and business owners, information owners or stewards, system owners, authorizing officials, senior agency information security officers, senior agency officials for privacy, and chief information officers.

Changes from Rev 4

New control in Rev 5. Risk framing activities formalized.

Compliance Mappings

ISO 27001:2022

6.1

ISO 27002:2022

5.34

COBIT 2019

APO12EDM03

NIST CSF 2.0

GV.OV-02GV.RM-01GV.RM-02GV.RM-03

MAS TRM

4

BIO2

5.34

RBI CSF

ITGRCA.22ITGRCA.25

FISC Security Guidelines

FISC.O1

HKMA TM-E-1

TME1.2.3TME1.7.1

DNB Good Practice

DNB.4.1DNB.4.2

SAMA CSF

1.8

NCA ECC

1-5

UAE IA

T2

CBB TM

TM-2TM-3TM-4

Qatar NIA

GVRM

CBUAE

CR-1CR-2

CBE CSF

CRM-1GOV-1

SA JS2

JS2-4JS2-5JS2-6.2

CBN CSF

Part1.1Part2.1Part2.2

BoG CISD

CISD-IICISD-III

BoM CTRM

1.11.4

BCBS 239

Principle 1

CPMI-IOSCO PFMI

PFMI.P3

FFIEC IS

II.B

ECB CROE

CROE.2.1.1CROE.2.2.1

EBA ICT Guidelines

3.3.13.3.3

SEBI CSCRF

GV.OCGV.RM

BOT Cyber Resilience

Ch1.2

CMMC 2.0

RA

DOE C2M2 v2.1

RISK

TIBER-EU

TIBER.CONFTIBER.PREP

Solvency II

Art.44(1)Art.44(2)Art.45DR.260EIOPA-ICT-4.2

Lloyd's Minimum Standards

MS10.1

FCA SYSC 13

SYSC 13.5.2SYSC 13.G.2

HITRUST CSF v11

00.b03.a

FDA Cybersecurity Guidance

SPDF-2

Basel SCO60

SCO60.3