Skip to main content

ER-24 Pre-Kickoff - Risk Assessment

Suzette Richards avatar
Written by Suzette Richards
Updated this week

Risk Management Policy and Procedures

Provide your risk management policy.

The evidence should demonstrate the:

  • Risk assessment process, including objectives, identification, rating, and mitigation

  • Requirement for risk assessments to be completed at least once per year

  • Requirement for policy to be reviewed and approved by management

Associated Unified Control ID

Associated Framework Control

CTRL-646

REQ-18, REQ-17, REQ-19, REQ-20

Did this answer your question?