{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-03","description":"The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"PM-28","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.RM-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.RM-06","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"31000-P2","coverage":"full","framework":"iso-31000","relationship":"superset_of"},{"control_id":"31000-PR2","coverage":"full","framework":"iso-31000","relationship":"superset_of"}],"statement":"The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.","title":"Define risk appetite, tolerance, and risk assessment criteria","unified_id":"UC-RISK-03"},"id":"uc:UC-RISK-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-03","sourceIds":["iso-31000","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0410e6d7cb4721cb921f9106fbdc7efe7756c179dc3f786e042f0d3ed94f5a79","properties":{},"sourceDetailPath":"/data/v1/records/wf-g11-62e4fa80.json","sourceId":"wf:G11","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0810351e17f27419b026c3722645fb72847323674b505082c6a8da3346e8d96a","properties":{"control_id":"31000-PR2","coverage":"full","delta":null,"framework":"iso-31000","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2018"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-iso-31000-31000-pr2-f0c97826.json","targetId":"ctrl:iso-31000:31000-PR2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c7112f7f5d9f6e6de0b21c723abc7ee1c5f42434ddb78e7fcd92ba9524151a5","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/risk-compliance-client-suitability-fiduciary-2212ad74.json","targetId":"risk:compliance-client-suitability-fiduciary","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:410320fc0890fabc7dbab7fb3ff149db2cc961b8b12dc9c38934fd82311dabd5","properties":{},"sourceDetailPath":"/data/v1/records/wf-g38-ec85d810.json","sourceId":"wf:G38","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:491879c8cb8b14f518463077e14630f7a4f1a7c89a4ee06d83c3673454f3a430","properties":{"rationale":"Defining risk appetite, tolerance and structured assessment criteria supplies the yardsticks without which risks cannot be consistently calculated, categorised or prioritised.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/risk-risk-assessment-inadequate-328128b5.json","targetId":"risk:risk-assessment-inadequate","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:672d5c71eb6d9412142d076ae9fe12c1e11241f627b91ab271a8bdf622432842","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e5305874e086b19506c4228a1162ad57764d1436f0cf33b7d80ffbb755ca34c","properties":{"control_id":"PM-28","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-28-d8441751.json","targetId":"ctrl:nist-800-53:PM-28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7003ab0e4d35ce9e5f6e3c2758435e92b712d4378bf32b826d59ba6664879e90","properties":{"control_id":"GV.RM-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-06-aa913e7b.json","targetId":"ctrl:nist-csf-2:GV.RM-06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a8319c2f1db21fe6e3398bafe3fbe34599762ebec37bf4b2c6bce0145c27c85","properties":{"control_id":"31000-P2","coverage":"full","delta":null,"framework":"iso-31000","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2018"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-iso-31000-31000-p2-48e44995.json","targetId":"ctrl:iso-31000:31000-P2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aae2adaa961ad38818a1f779929abea6a131364f57df2364c5fadcc346ae55ff","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5934e0c4b9dbe574eebb2cb750a66a1e9792051bef88c279d12261ea0474948","properties":{"control_id":"GV.RM-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-02-5a997df0.json","targetId":"ctrl:nist-csf-2:GV.RM-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9b750e24069726b3fcb005c77f821cc396e7624e27ce12e12484a783aa77964","properties":{},"sourceDetailPath":"/data/v1/records/wf-g3-4c4dc6e1.json","sourceId":"wf:G3","targetDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","targetId":"uc:UC-RISK-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4614d739e72ff5fabf08afc4dc713798860b3f812dac531578255ac8836640a","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/risk-strategic-concentration-816dfff6.json","targetId":"risk:strategic-concentration","type":"mitigates"}],"schemaVersion":1}
