unified

UC-AUDIT-22 — Review risk strategy and performance with leadership

Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Compliance, Audit & Assurance
type
detective
category
administrative

Details

unified_id
UC-AUDIT-22
title
Review risk strategy and performance with leadership
statement
Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.
domain
Compliance, Audit & Assurance
control_type
detective
control_category
administrative
members
  • framework
    nist-csf-2
    control_id
    GV.OV-02
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.OV-03
    coverage
    full
    relationship
    superset_of
  • framework
    cobit-2019
    control_id
    MEA01
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections