NIST SP 800-53 Rev. 5
RA-3
Risk Assessment

Risk Assessment

Description

a. Conduct a risk assessment, including: b. Integrate risk assessment results and risk management decisions from the organization and mission or business process perspectives with system-level risk assessments; c. Document risk assessment results in [organization-defined parameter]; d. Review risk assessment results [organization-defined parameter]; e. Disseminate risk assessment results to [organization-defined parameter] ; and f. Update the risk assessment [organization-defined parameter] or when there are significant changes to the system, its environment of operation, or other conditions that may impact the security or privacy state of the system.

Mapped SPARTA techniques

81 techniques

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Referenced by 16 in NIST Cybersecurity Framework 2.0

Cite as SafeMode Space, nist-80053-rev5 RA-3.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.