Cybersecurity risk management activities are not informed and supported by organisational risk criteria (RISK-2d, RISK-3b)
Context and Guidance: RISK-2d AND RISK-3b must be at least "Partially Implemented" for this Anti-Pattern to be "Not Present".
Cybersecurity risk management activities should be informed and supported by organisational risk criteria.
This ensures that cybersecurity risks can be consolidated from many functions, and aggregated into one or many organisational risks. It also ensures a consistent approach to risk assessment and grading is used.