A strategy for cyber risk management is established and maintained in alignment with the organization’s cybersecurity program strategy (PROGRAM-1b) and enterprise architecture
The risk management strategy is kept current and relevant. A risk management strategy focused on mitigating risks of procured software, for example, will likely be out of step with a cybersecurity program goal of increasing internally developed software and an enterprise architecture goal implementing a secure development process.
Related Practices · Dependency: Implementing this practice depends upon prior implementation of PROGRAM-1b. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-1a, RISK-1b, RISK-1c, RISK-1g, RISK-1h.