Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 1.06 KB

prm-06-businessprocessdefinition.md

File metadata and controls

19 lines (17 loc) · 1.06 KB

SCF - PRM-06 - Business Process Definition

Mechanisms exist to define business processes with consideration for cybersecurity & data privacy that determines:

  • The resulting risk to organizational operations, assets, individuals and other organizations; and
  • Information protection needs arising from the defined business processes and revises the processes as necessary, until an achievable set of protection needs is obtained.

Mapped framework controls

SOC 2

Control questions

Does the organization define business processes with consideration for cybersecurity & data privacy that determines:

  • The resulting risk to organizational operations, assets, individuals and other organizations; and
  • Information protection needs arising from the defined business processes and revises the processes as necessary, until an achievable set of protection needs is obtained?