GRM-11: Risk Management Framework

Warning icon.

Control is withdrawn in the next version of this control set and incorporated into: A&A-06: Remediation, GRC-02: Risk Management Program.

Control Statement

Risks shall be mitigated to an acceptable level. Acceptance levels based on risk criteria shall be established and documented in accordance with reasonable resolution time frames and stakeholder approval.

[ Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]

Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.