graphgrc

SCF - CPL-01.1 - Non-Compliance Oversight

Mechanisms exist to document and review instances of non-compliance with statutory, regulatory and/or contractual obligations to develop appropriate risk mitigation actions.

Mapped framework controls

ISO 27001

Control questions

Does the organization document and review instances of non-compliance with statutory, regulatory and/or contractual obligations to develop appropriate risk mitigation actions?