unified
UC-RISK-04 — Define objectives and business context for risk assessment
The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-04
- title
- Define objectives and business context for risk assessment
- statement
- The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-11
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P6
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC3.1
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOC 2 Trust Services Readiness tests UC-RISK-04 — Define objectives and business context for risk assessment
- UC-RISK-04 — Define objectives and business context for risk assessment maps_to CC3.1 — The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
- framework
- soc2
- control_id
- CC3.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-04 — Define objectives and business context for risk assessment
- UC-RISK-04 — Define objectives and business context for risk assessment mitigates Strategic misalignment and execution failure
- strength
- related
- rationale
- COSO P6 member requires objectives specified with clarity and consistency, reducing the poorly-defined/inconsistent-objective driver of strategic misalignment (partial contributor).
- Risk Assessment and Treatment Review operates UC-RISK-04 — Define objectives and business context for risk assessment
- Strategic Context & Objectives Alignment Cycle operates UC-RISK-04 — Define objectives and business context for risk assessment
- UC-RISK-04 — Define objectives and business context for risk assessment mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Specifying objectives and business context clearly is the foundation that makes risk identification and assessment possible; absent it the process is inadequate.
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-04 — Define objectives and business context for risk assessment
- UC-RISK-04 — Define objectives and business context for risk assessment maps_to P6 — The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
- framework
- coso-ic
- control_id
- P6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-04 — Define objectives and business context for risk assessment maps_to PM-11 — Mission and Business Process Definition
- framework
- nist-800-53
- control_id
- PM-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.