April 16, 2018
Function
Category
Risk Management Strategy
(ID.RM): The organization’s
priorities, constraints, risk
tolerances, and assumptions are
established and used to support
operational risk decisions.
Cybersecurity Framework
Subcategory
Version 1.1
Informative References
ID.RA-3: Threats, both internal and
external, are identified and documented
CIS CSC 4
COBIT 5 APO12.01, APO12.02, APO12.03,
APO12.04
ISA 62443-2-1:2009 4.2.3, 4.2.3.9, 4.2.3.12
ISO/IEC 27001:2013 Clause 6.1.2
NIST SP 800-53 Rev. 4 RA-3, SI-5, PM-12, PM16
ID.RA-4: Potential business impacts and
likelihoods are identified
CIS CSC 4
COBIT 5 DSS04.02
ISA 62443-2-1:2009 4.2.3, 4.2.3.9, 4.2.3.12
ISO/IEC 27001:2013 A.16.1.6, Clause 6.1.2
NIST SP 800-53 Rev. 4 RA-2, RA-3, SA-14, PM9, PM-11
ID.RA-5: Threats, vulnerabilities,
likelihoods, and impacts are used to
determine risk
CIS CSC 4
COBIT 5 APO12.02
ISO/IEC 27001:2013 A.12.6.1
NIST SP 800-53 Rev. 4 RA-2, RA-3, PM-16
ID.RA-6: Risk responses are identified and
prioritized
CIS CSC 4
COBIT 5 APO12.05, APO13.02
ISO/IEC 27001:2013 Clause 6.1.3
NIST SP 800-53 Rev. 4 PM-4, PM-9
ID.RM-1: Risk management processes are
established, managed, and agreed to by
organizational stakeholders
CIS CSC 4
COBIT 5 APO12.04, APO12.05, APO13.02,
BAI02.03, BAI04.02
ISA 62443-2-1:2009 4.3.4.2
ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3,
Clause 9.3
NIST SP 800-53 Rev. 4 PM-9
COBIT 5 APO12.06
ISA 62443-2-1:2009 4.3.2.6.5
ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3
NIST SP 800-53 Rev. 4 PM-9
ID.RM-2: Organizational risk tolerance is
determined and clearly expressed
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
27