Risk-Based Security Categorization
Mechanisms exist to categorize Technology Assets, Applications, Services and/or Data (TAASD) in accordance with applicable laws, regulations and contractual obligations that: (1) Document the security categorization results (including supporting rationale) in the security plan for systems; and (2) Ensure the security categorization decision is reviewed and approved by the asset owner.
Does the organization categorize Technology Assets, Applications, Services and/or Data (TAASD) in accordance with applicable laws, regulations and contractual obligations that: (1) Document the security categorization results (including supporting rationale) in the security plan for systems; and (2) Ensure the security categorization decision is reviewed and approved by the asset owner?
Risk Management
Annual
E-RSK-01 E-RSK-04 E-BCM-08 E-TPM-02
This control maps to the following compliance frameworks
4.2.1
1.11.21.31.41.52.12.22.3
