ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
PF v1.0 References:
Subcategory is withdrawn in the next version of this framework and incorporated into: GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders, GV.RM-06: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated, GV.RR-03: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies.
Description
[csf.tools Note: Subcategories do not have detailed descriptions.]