Risk Response
What is Risk Response?
The selection and implementation of options for addressing risk, including avoidance, reduction, sharing, transfer, or acceptance.
Terms that appear alongside risk response
Each of these is named in at least one of the same controls as risk response. The number is how many controls name both.
- nist 3 shared controls
- risk tolerance 2 shared controls
- authorisation 2 shared controls
- supply chain risk 2 shared controls
Frameworks that govern risk response
What the standards actually require on risk response
Requirements naming risk response across 6 standards, quoted from the control text.
Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-04 · Strategic direction that describes appropriate risk response options is established and communicated →Requires findings raised by assessments, monitoring activity and audits, covering both security and privacy, to be responded to in line with the organization's stated risk tolerance, so each is remediated, mitigated, transferred or formally accepted.
NIST800-RA-7 · Risk response →Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.
RA-7 · Risk Response →Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.
RA-7 · Risk Response →Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so that identified risk is treated rather than only recorded.
fedramp-moderate::RA-7 · Risk Response →Responses to the AI risks deemed high priority as identified by the Map function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.
AIRMF-MN-1.3 · Responses to the AI risks deemed high priority as identified by the MAP function are developed, planned, and documented, and risk response options can include mitigating, transferring, avoiding, or accepting →Questions people ask about risk response
What is Risk Response?
Why is Risk Response important for compliance?
Which compliance frameworks address Risk Response?
Where can I learn more about Risk Response?
See how Risk Response applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.