Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Risk level accepted by the organization

Critical
High
Normal
Low

The organization must determine an acceptable level for risks. The level is calculated based on the likelihood, impact and control of the risks.

Connected other frameworks and requirements:
ID.RM-2: Risk tolerance
NIST CSF
ID.RM-3: Informing of risk tolerance
NIST CSF
6.1: Information security risk management
ISO 27001
3.1 (MIL1): Establish and Maintain Cyber Risk Management Strategy and Program
C2M2
No items found.