Results from cyber risk impact analyses and cybersecurity control evaluations are reviewed together by enterprise leadership to determine whether cyber risks are sufficiently mitigated, and risk tolerances are not exceeded
Context and Guidance: Unique insight can be gained from the fusion of results from cyber risk impact analyses and cybersecurity control evaluations. For example, enterprise leadership may determine that moving some systems to the cloud increases availability and improves operations of an organisation, but a cybersecurity control evaluation finds that misconfigurations of the environment could lead to compromise of confidentiality.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-3b, RISK-3c, RISK-4c, RISK-4d.