3.2—3.2
>Control Description
Based on the results of the risk assessment, the individual entities must document how identified risks will be mitigated. As a minimum, this includes clearly identifying an integrated set of logical, physical, and personnel security controls to be implemented and the underlying rationale for a control selection based on a cost-benefit analysis.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.