GRC-02: Is there an established formal, documented, and leadership-sponsored enterprise
risk management (ERM) program that includes policies and procedures for identification,
evaluation, ownership, treatment, and acceptance of cloud security and privacy
risks?
The enterprise risk management (ERM) program should consider—and not be limited to—cloud-related information security and data privacy risks. The program should include risk management elements such as risk identification, risk assessment, risk treatment, and risk reporting. Management of each business area should consist of the implementation of the applicable ERM program policies and procedures. The ERM program should also feature a formal statement of risk appetite and may include creating and maintaining a risk register that reflects the likelihood of occurrence, potential business impacts, risk levels, and proposed mitigation actions for each risk.
Control implemented
Control ownership
Description
Establish a formal, documented, and leadership-sponsored Enterprise
Risk Management (ERM) program that includes policies and procedures for identification,
evaluation, ownership, treatment, and acceptance of cloud security and privacy
risks.