# PM-29 Risk Management Program Leadership Roles

NIST SP 800-53 control. Family: PM Program Management. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: a. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and b. Establish a Risk Executive (function) to view and analyze risk from an organization-wide perspective and ensure management of risk is consistent across the organization.
Guidance: The senior accountable official for risk management leads the risk executive (function) in organization-wide risk management activities.

## Patterns that use it (1)
- Important (1): SP-018 Information Security Management System

## Clauses by framework (34 frameworks)
- iso_27001_2022: 5.1, 5.2, 5.3, 9.3, A.5.2, A.5.4. OSA's own, not in NIST's crosswalk: A.5.4
- iso_27002_2022: 5.4
- nist_csf_2: GV.RR-01, GV.RR-02
- pra_op_resilience: SS1/21-3.2
- bio2: 5.4
- rbi_csf: Annex1.11, ITGRCA.10
- hkma_tme1: TME1.2.1, TME1.2.4
- dnb_good_practice: DNB.5.1
- cbb_tm: TM-1
- cbuae: CR-1
- nca_ecc: 1-1, 1-2, 1-4
- sama_csf: 1.1, 1.8
- uae_ia: T1
- bog_cisd: CISD-II
- bom_ctrm: 1.1, 1.2
- cbe_csf: GOV-1, GOV-2
- cbn_csf: Part1.1, Part1.2
- sa_js2: JS2-4
- bcbs_239: Principle 1
- cpmi_pfmi: CG.GOV, PFMI.P2
- eba_ict: 3.2.1, 3.3.1
- ecb_croe: CROE.2.1.1, CROE.2.1.2
- ffiec_is: I.B
- nydfs_500: 500.4
- sebi_cscrf: GV.RM
- cbest: CBEST.1
- tiber_eu: TIBER.PREP
- fca_sysc_13: SYSC 13.1-2, SYSC 13.6.3, SYSC 13.G.1
- iso_27799: 6.1
- lloyds_ms: CRM.1, GOV.1, MS8.1, MS10.1
- naic_ds: 4C
- nhs_dspt: NDG-1.2
- pra_ss1_23: P2.1
- solvency_ii: Art.41(1), Art.44(1), DR.258, DR.260, EIOPA-ICT-4.1
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PM-29
- Clauses only: /api/v1/controls/PM-29?fields=mappings
- Page for people: /controls/pm-29/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
