PM-9
Program Management
Risk Management Strategy
Description
a. Develops a comprehensive strategy to manage: b. Implement the risk management strategy consistently across the organization; and c. Review and update the risk management strategy [organization-defined parameter] or as required, to address organizational changes.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 17 in NIST Cybersecurity Framework 2.0
- DE.AE-04The estimated impact and scope of adverse events are understood
- GV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- GV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
- GV.RM-01Risk management objectives are established and agreed to by organizational stakeholders
- GV.RM-02Risk appetite and risk tolerance statements are established, communicated, and maintained
- GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
- GV.RM-04Strategic direction that describes appropriate risk response options is established and communicated
- GV.RM-05Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
- GV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- GV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- GV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated
- PR.IR-04Adequate resource capacity to ensure availability is maintained
- RC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
Referenced by 1 in NASA Best Practices Guide for Mission Cybersecurity
Cite as SafeMode Space, nist-80053-rev5 PM-9.