According to this article Understanding the Recent FFIEC Guidance we are required to have the Board approve our Risk Assessment and Mitigation Strategy. Can anyone tell me where to find this in the FFIEC's Guidance?