RA-2
Risk Assessment
Security Categorization
Description
a. Categorize the system and information it processes, stores, and transmits; b. Document the security categorization results, including supporting rationale, in the security plan for the system; and c. Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 3 in NIST Cybersecurity Framework 2.0
- ID.AM-05Assets are prioritized based on classification, criticality, resources, and impact on the mission
- ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
- ID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Cite as SafeMode Space, nist-80053-rev5 RA-2.