unified

UC-RISK-06 — Perform periodic enterprise risk assessments

The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Risk Assessment & Management
type
preventive
category
administrative

Details

unified_id
UC-RISK-06
title
Perform periodic enterprise risk assessments
statement
The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.
domain
Risk Assessment & Management
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    RA-3
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC3.2
    coverage
    full
    relationship
    superset_of
  • framework
    coso-ic
    control_id
    P7
    coverage
    full
    relationship
    superset_of
  • framework
    sox
    control_id
    ELC-RA
    coverage
    partial
    delta
    objective-setting, fraud, and change aspects covered by dedicated unified controls
    relationship
    intersects_with
  • framework
    nydfs-500
    control_id
    500.9
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections