Back

Document and justify any exclusions from the scope of the risk management activities in the risk management program.


CONTROL ID
15336
CONTROL TYPE
Business Processes
CLASSIFICATION
Detective

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Include the scope of risk management activities in the risk management program., CC ID: 13658

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • Additionally, the organization should provide justification for any exclusion from the scope. (§ 7.3 ¶ 5, ISO/IEC 27005:2018, Information Technology — Security Techniques — Information Security Risk Management, Third Edition)