unified

UC-RISK-04 — Define objectives and business context for risk assessment

The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Risk Assessment & Management
type
preventive
category
administrative

Details

unified_id
UC-RISK-04
title
Define objectives and business context for risk assessment
statement
The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.
domain
Risk Assessment & Management
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    PM-11
    coverage
    full
    relationship
    superset_of
  • framework
    coso-ic
    control_id
    P6
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC3.1
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections