ID.RM-2.1: The organization shall clearly determine it’s risk appetite.
Determination and expression of risk tolerance (risk appetite) should be in line with the policies on information security and cybersecurity, to facilitate demonstration of coherence between policies, risk tolerance and measures.
Documentation Maturity
Implementation Maturity
Description
The organization shall clearly determine it’s risk appetite.