Cybersecurity Risk
What is Cybersecurity Risk?
The potential for financial loss, operational disruption, or reputational damage resulting from the failure of digital technologies and cyber threats.
Terms that appear alongside cybersecurity risk
Each of these is named in at least one of the same controls as cybersecurity risk. The number is how many controls name both.
- cybersecurity 65 shared controls
- risk assessment 19 shared controls
- governance 10 shared controls
- risk treatment 5 shared controls
- compliance 4 shared controls
- vulnerability 4 shared controls
- access control 4 shared controls
- crisis management 4 shared controls
Frameworks that govern cybersecurity risk
What the standards actually require on cybersecurity risk
Requirements naming cybersecurity risk across 6 standards, quoted from the control text.
The organizational mission is understood and informs cybersecurity risk management
NIST-CSF-GV.OC-01 · The organizational mission is understood and informs cybersecurity risk management →Article 25 establishes the MEMBER STATE cybersecurity risk assessment - the third level of the four-level cascade. Member State competent authorities conduct national cybersecurity risk assessments for their in-scope electricity entities, building on the Union...
NCCS-Art.25_26 · Member State cybersecurity risk assessment (NCCS Articles 25-26) - third level of the cascade →The entity has to be able to say whether its measures work, not merely that they exist. That calls for a defined assessment approach with a schedule, someone sufficiently independent of the people who operate the control doing the assessing, criteria for what...
nis2-directive::Art.21.2.f · Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures →For each zone and conduit perform detailed risk assessment identifying threats, vulnerabilities, existing countermeasures, likelihood, consequence and resulting risk against tolerable risk, leading to target Security Level SL-T.
62443-3-2-ZCR-4 · Detailed Cybersecurity Risk Assessment per Zone and Conduit →Describe the board of directors' oversight of risks from cybersecurity threats, identifying any board committee or subcommittee responsible for the oversight and the processes by which the board or committee is informed about such risks.
SEC-CYB-08 · Board Oversight of Cybersecurity Risks →Article 54 sets the procedure at national level concerning PDEs presenting a significant cybersecurity risk: the market surveillance authority can order corrective action, withdrawal or recall from the market within a reasonable period.
CRA-Art.54_55 · Significant cybersecurity risk procedure and Union safeguard (Articles 54-55) →Questions people ask about cybersecurity risk
What is Cybersecurity Risk?
Why is Cybersecurity Risk important for compliance?
Which compliance frameworks address Cybersecurity Risk?
Where can I learn more about Cybersecurity Risk?
See how Cybersecurity Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.