RSK-04—Risk Assessment
Weight: 10
>Control Description
Mechanisms exist to conduct recurring assessments of risk that includes the likelihood and magnitude of harm, from unauthorized access, use, disclosure, disruption, modification or destruction of the organization's Technology Assets, Applications, Services and/or Data (TAASD).
>Cross-Framework Mappings
ISO 27001:2022
CMMC v2.0
NIST AI RMF
EU AI Act
Canada ITSP 10.171
EU AI Act (Detailed)
SOC 2 TSC (Detailed)
ISO 27001:2022 (Detailed)
ISO 42001:2023 (Detailed)
NIST SP 800-171 Rev 3
NIST SP 800-171A Rev 3
GLBA (16 CFR 314)
HIPAA Simplification 2013
NERC CIP
SEC Cybersecurity Rule
Ask AI
Configure your API key to use AI features.