a. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and
b. Establish a Risk Executive (function) to view and analyze risk from an organization-wide perspective and ensure management of risk is consistent across the organization.
|
|
| Control Identifier | PM-29 |
| Latest Sync Date | 19/12/24 09:18:14 |
| Discussion | The senior accountable official for risk management leads the risk executive (function) in organization-wide risk management activities. |
| Related Controls | PM-2, PM-19. |