03.11.04: Risk Response

Control Family:

Risk Assessment

CSF v1.1 References:

Info icon.

Control is new to this version of the control set.

Requirements

  1. Respond to findings from security assessments, monitoring, and audits.

Discussion

This requirement addresses the need to determine an appropriate response to risk before generating a plan of action and milestones (POAM) entry. It may be possible to mitigate the risk immediately so that a POAM entry is not needed. However, a POAM entry is generated if the risk response is to mitigate the identified risk and the mitigation cannot be completed immediately.