The organization shall conduct risk assessments in which risk is determined by threats, vulnerabilities and impact on business processes and assets.
The organization shall conduct and document risk assessments in which risk is determined by threats, vulnerabilities, impact on business processes and assets, and the likelihood of their occurrence.
Risk assessment results shall be disseminated to relevant stakeholders.