A defined method is used to identify cyber risks
A defined method is planned in advance, clearly described, made definite, and standardized. Employing a defined method to identify risks will aid the cyber risk management program in producing consistent outputs and better enable effective management of cyber risk. The organization may choose to define their own method or leverage standardized guidance, such as the NIST SP 800-30, Guide for Conducting Risk Assessments.
Related Practices · Input From: Implementing THIRD-PARTIES-1c provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-2a, RISK-2b, RISK-2c, RISK-2g, RISK-2h, RISK-2i, RISK-2j, RISK-2k, RISK-2l, RISK-2m.