Under active development Content is continuously updated and improved

3.23.2

>Control Description

Based on the results of the risk assessment, the individual entities must document how identified risks will be mitigated. As a minimum, this includes clearly identifying an integrated set of logical, physical, and personnel security controls to be implemented and the underlying rationale for a control selection based on a cost-benefit analysis.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.