GV.RM-03.020
Has your organization established formal criteria for escalating cybersecurity risks to senior management within your enterprise risk management framework?
Explanation
Cybersecurity risk escalation criteria define the thresholds, conditions, and processes for elevating significant security concerns to appropriate leadership levels for awareness and decision-making. Without clear escalation paths, critical security issues may remain unaddressed at operational levels, potentially leading to delayed responses to serious threats or incidents. Evidence could include a documented risk escalation matrix or procedure that defines specific thresholds (e.g., risk scores above a certain level, specific threat types, potential financial impact exceeding defined amounts), escalation timeframes, and the appropriate management levels for different risk categories.
Implementation Example
Establish criteria for escalating cybersecurity risks within enterprise risk management
ID: GV.RM-03.020
Context
- Function
- GV: GOVERN
- Category
- GV.RM: Risk Management Strategy
- Sub-Category
- Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

