unified
UC-RISK-07 — Identify and analyze risks and opportunities to objectives
Risks and strategic opportunities (positive risks) are systematically identified at entity and process levels, and each identified risk is analyzed for likelihood and potential impact using the best available historical, current, and forward-looking information. Severity is assessed with consistent scales to support comparison across the risk universe. Results, sources, and analysis assumptions are recorded.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-07
- title
- Identify and analyze risks and opportunities to objectives
- statement
- Risks and strategic opportunities (positive risks) are systematically identified at entity and process levels, and each identified risk is analyzed for likelihood and potential impact using the best available historical, current, and forward-looking information. Severity is assessed with consistent scales to support comparison across the risk universe. Results, sources, and analysis assumptions are recorded.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-31000
- control_id
- 31000-PR3
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-PR4
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-P6
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E10
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E11
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.RA-04
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-07
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ERM Risk Identification & Register Refresh operates UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to ID.RA-04 — Risk Assessment: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- framework
- nist-csf-2
- control_id
- ID.RA-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to E10 — Identifies Risk
- framework
- coso-erm
- control_id
- E10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to E11 — Assesses Severity of Risk
- framework
- coso-erm
- control_id
- E11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives mitigates Money laundering, sanctions and financial-crime program failures
- strength
- related
- rationale
- Annual ICFR Scoping & Risk Assessment oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Systematic risk identification and likelihood/impact analysis with consistent severity scales is the analytic core of the risk-assessment process.
- Risk & Control Self-Assessment (RCSA) Program operates UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to GV.RM-07 — Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
- framework
- nist-csf-2
- control_id
- GV.RM-07
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives mitigates Product, customer or market concentration
- strength
- related
- rationale
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- ESG-Related Risk Materiality & Integration oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to 31000-PR3 — Risk assessment: risk identification
- framework
- iso-31000
- control_id
- 31000-PR3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to 31000-P6 — Best available information
- framework
- iso-31000
- control_id
- 31000-P6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Emerging Risk & Horizon Scan operates UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- Risk Assessment and Treatment Review operates UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- Risk Register Intake oversees UC-RISK-07 — Identify and analyze risks and opportunities to objectives
- UC-RISK-07 — Identify and analyze risks and opportunities to objectives maps_to 31000-PR4 — Risk assessment: risk analysis
- framework
- iso-31000
- control_id
- 31000-PR4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.