RSK-11
Risk Monitoring
Description
Mechanisms exist to ensure risk monitoring as an integral part of the continuous monitoring strategy that includes monitoring the effectiveness of cybersecurity and data protection controls, compliance and change management.
Control Question
Does the organization ensure risk monitoring as an integral part of the continuous monitoring strategy that includes monitoring the effectiveness of cybersecurity and data protection controls, compliance and change management?
Control Metadata
Domain:
Risk Management
Validation Cadence:
Annual
