unified
UC-RISK-02 — Integrate risk management into enterprise processes and projects
Risk management is integrated into organizational structures, decision-making, and business activities rather than operated as a standalone silo. Cybersecurity and information security risk activities are incorporated into enterprise risk management processes, and information security risk is addressed within project management for all projects from initiation through delivery. ERM artifacts referencing cyber risk and project gate documentation with security risk sections evidence operation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-02
- title
- Integrate risk management into enterprise processes and projects
- statement
- Risk management is integrated into organizational structures, decision-making, and business activities rather than operated as a standalone silo. Cybersecurity and information security risk activities are incorporated into enterprise risk management processes, and information security risk is addressed within project management for all projects from initiation through delivery. ERM artifacts referencing cyber risk and project gate documentation with security risk sections evidence operation.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-31000
- control_id
- 31000-P1
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-FW2
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-03
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.8
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-02 — Integrate risk management into enterprise processes and projects maps_to 31000-P1 — Integrated
- framework
- iso-31000
- control_id
- 31000-P1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-02 — Integrate risk management into enterprise processes and projects maps_to 31000-FW2 — Integration
- framework
- iso-31000
- control_id
- 31000-FW2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-02 — Integrate risk management into enterprise processes and projects mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- GV.RM-03 member folds cyber risk into ERM, giving threats enterprise governance and resourcing, an enabler rather than the operative defense against attackers.
- UC-RISK-02 — Integrate risk management into enterprise processes and projects maps_to GV.RM-03 — Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
- framework
- nist-csf-2
- control_id
- GV.RM-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ESG-Related Risk Materiality & Integration oversees UC-RISK-02 — Integrate risk management into enterprise processes and projects
- UC-RISK-02 — Integrate risk management into enterprise processes and projects mitigates Credit and market (rate/FX) risk
- strength
- related
- rationale
- UC-RISK-02 — Integrate risk management into enterprise processes and projects maps_to A.5.8 — Information security in project management
- framework
- iso-27001
- control_id
- A.5.8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Technology Investment & Project Risk Governance operates UC-RISK-02 — Integrate risk management into enterprise processes and projects
- UC-RISK-02 — Integrate risk management into enterprise processes and projects mitigates Major project / program delivery failure
- strength
- related
- rationale
- A.5.8 member requires infosec risk addressed in project management from initiation to delivery, contributing to project governance and fewer delivery surprises.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-RISK-02 — Integrate risk management into enterprise processes and projects