ID.RA: Risk Assessment
Next Version:
- NIST Cybersecurity Framework v2.0:
- ID.RA: Risk Assessment
Description
The organization understands the cybersecurity risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals.
Framework Subcategories
ID.RA-1: Asset vulnerabilities are identified and documented
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.RA-2: Cyber threat intelligence is received from information sharing forums and sources
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.RA-3: Threats, both internal and external, are identified and documented
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.RA-4: Potential business impacts and likelihoods are identified
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.RA-5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.RA-6: Risk responses are identified and prioritized
[csf.tools Note: Subcategories do not have detailed descriptions.]