unified
UC-RISK-08 — Evaluate and prioritize risks against risk criteria
Analyzed risks are evaluated against the established risk criteria to determine inherent risk and whether treatment is required. Risks are prioritized based on severity, risk appetite, and organizational context to direct treatment resources and response sequencing. Prioritization outcomes and rationale are documented and communicated to risk owners.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-08
- title
- Evaluate and prioritize risks against risk criteria
- statement
- Analyzed risks are evaluated against the established risk criteria to determine inherent risk and whether treatment is required. Risks are prioritized based on severity, risk appetite, and organizational context to direct treatment resources and response sequencing. Prioritization outcomes and rationale are documented and communicated to risk owners.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-31000
- control_id
- 31000-PR5
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E12
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.RA-05
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Evaluating and prioritising analyzed risks against criteria to decide treatment is a core process step countering an assessment that never reaches decisions.
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria maps_to ID.RA-05 — Risk Assessment: Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
- framework
- nist-csf-2
- control_id
- ID.RA-05
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria mitigates Trade-counterparty performance and settlement disputes
- strength
- related
- rationale
- Risk Register Intake oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- FSLI Significance Assessment operates UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- Risk Assessment and Treatment Review operates UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- ISMS Risk Assessment & Treatment Cycle oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria maps_to 31000-PR5 — Risk assessment: risk evaluation
- framework
- iso-31000
- control_id
- 31000-PR5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Risk & Control Self-Assessment (RCSA) Program operates UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- Policy Exception & Risk Acceptance oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- Enterprise Risk Treatment Operations Cycle operates UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- UC-RISK-08 — Evaluate and prioritize risks against risk criteria maps_to E12 — Prioritizes Risks
- framework
- coso-erm
- control_id
- E12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOX Scoping Decision oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria
- ESG-Related Risk Materiality & Integration oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria