GV.RM-06.028

Has your organization established formal criteria for prioritizing identified risks across different levels of the enterprise?

Explanation

Risk prioritization criteria help organizations make consistent decisions about which risks require immediate attention versus those that can be addressed later or accepted. These criteria should be tailored to different organizational levels (e.g., strategic, operational, project) and consider factors such as potential financial impact, regulatory compliance implications, and effect on business operations.

Evidence could include a documented risk prioritization framework or matrix that defines how risks are scored and ranked, meeting minutes showing risk prioritization discussions, or a risk register that demonstrates consistent application of prioritization criteria across the enterprise.

Implementation Example

Establish criteria for risk prioritization at the appropriate levels within the enterprise

ID: GV.RM-06.028

Context

Function
GV: GOVERN
Category
GV.RM: Risk Management Strategy
Sub-Category
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

Related questions