Risk, control and execution assessment
Risk in context, assessment, mitigation measure, control and execution. Requirement, policy and evidence are imported by reference.
Research draft, second pass
A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.
Bundle → Layer → Finding → Questions Missing, in the backlog
Not described yet. This gap is in the card backlog.
Note: Research contour: bundles not designed yet; questions are listed as open questions.
Classifiers Filled
- Family
- Enterprise profiles
- Category
- Enterprise subject
- Entry kind
- subject
- Domain
- EnterpriseRSK
- Industry
- Cross-industry
- Tags
- EM-RSK-01W1subjectRiskRiskAssessmentRiskTreatmentControlControlExecution
What it is Filled
Risk in context, assessment, mitigation measure, control and execution. Requirement, policy and evidence are imported by reference.
Why it exists Filled
Risk in context, assessment, mitigation measure, control and execution. Requirement, policy and evidence are imported by reference.
Distinguishing features Derived, awaiting review
- An assessment contains a scale and a horizon
- The presence of a control does not prove effectiveness
- Residual risk has grounds
What robots and AI may and may not do Derived, awaiting review
Must not
- Negative case: A green policy status automatically closes all related risks.
Note: Negative case of the research brief, not yet a rule for agents.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
Владелец рисков / CISO / внутренний аудит
Master systems
- GRC
- IAM
- SIEM
- сервис-деск
Links to other meta-models Filled
neighbor
- EM-LEG-02
- EM-OPS-01
- EM-PRD-01
- EM-RSK-02
- EM-STR-02
- EM-TEC-04
references
- WM-KNW-015 - conceptual-candidate
- WM-XCT-027 - conceptual-candidate
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Derived, awaiting review
- Risk
- RiskAssessment
- RiskTreatment
- Control
- ControlExecution
Direct properties not applicable Not applicable
Not applicable
Enterprise record contour: physical properties belong to referenced world models.
Recognition required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Hazards and failure modes required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Context of use required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Sources Filled
- NIST CSF/AI RMF: governance and risk functions
- ODRL/PROV: authority, grounds and evidence
- GRC/IAM/BCM practice and NIST SP 800-34 for recovery
Open questions
- How to compare assessments on different scales?
- How to separate control design from its execution?
- When do several risks share a common cause?
- Установить границу и решение reuse/extend/new по действующим спецификациям.
- Подтвердить semantic crosswalk, права и source mastership.
- Выбрать immutable refs; провести проверки fixtures до заявления о публикационной готовности.
Machine files
Provenance
enterprise research programme · published-partial
Built from: enterprise/models/em-rsk-01/brief.json
Still in Russian: suggested owner, blocking decisions, vercy candidates. Translate in research/enterprise/i18n/units.en.json.