Requirement
The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
risk assessmentrisk identificationrisk register
Required element 2 — any one of
objectivescopecriteria
Supporting terms — specificity signals
likelihoodimpactthreatannualmethodology
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| PCI DSS 4.0.1 | 12.3.1 | Targeted risk analyses | risk-assessment |
| HIPAA | 164.308(a)(1)(ii)(A) | Risk analysis (R) | risk-assessment |
| HIPAA | 164.308(a)(1)(ii)(B) | Risk management (R) | risk-assessment |
| GLBA | 314.4(b) | Written risk assessment | risk-assessment |
| NIST CSF 2.0 | ID.RA-05 | Risks are prioritised to inform response | risk-assessment |
| GDPR | Art.35 | Data protection impact assessment | risk-assessment |
| GDPR | Art.36 | Prior consultation with the supervisory authority | risk-assessment |
| CCPA/CPRA | Regs (risk assessments) | Risk assessments for significant-risk processing | risk-assessment |