PM-28
Program Management
Risk Framing
Description
a. Identify and document: b. Distribute the results of risk framing activities to [organization-defined parameter] ; and c. Review and update risk framing considerations [organization-defined parameter].
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 6 in NIST Cybersecurity Framework 2.0
- DE.AE-04The estimated impact and scope of adverse events are understood
- GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
- GV.RM-04Strategic direction that describes appropriate risk response options is established and communicated
- GV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- GV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
- GV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
Referenced by 1 in NASA Best Practices Guide for Mission Cybersecurity
Cite as SafeMode Space, nist-80053-rev5 PM-28.