NIST Cybersecurity Framework (CSF) 2.0 2.0

ID.RA

Risk Assessment

The cybersecurity risk to the organization, assets, and individuals is understood by the organization

Citation ID.RA
Clé de plateforme arcate:compliance:requirements/nist-csf/2.0/ID.RA
Emplacement dans la source row 52 of sheet 'CSF 2.0'
Publié par NIST

Exigences filles

ID.RA-01

Vulnerabilities in assets are identified, validated, and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-01

ID.RA-02

Cyber threat intelligence is received from information sharing forums and sources

arcate:compliance:requirements/nist-csf/2.0/ID.RA-02

ID.RA-03

Internal and external threats to the organization are identified and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-03

ID.RA-04

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

arcate:compliance:requirements/nist-csf/2.0/ID.RA-04

ID.RA-05

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

arcate:compliance:requirements/nist-csf/2.0/ID.RA-05

ID.RA-06

Risk responses are chosen, prioritized, planned, tracked, and communicated

arcate:compliance:requirements/nist-csf/2.0/ID.RA-06

ID.RA-07

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

arcate:compliance:requirements/nist-csf/2.0/ID.RA-07

ID.RA-08

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

arcate:compliance:requirements/nist-csf/2.0/ID.RA-08

ID.RA-09

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

arcate:compliance:requirements/nist-csf/2.0/ID.RA-09

ID.RA-10

Critical suppliers are assessed prior to acquisition

arcate:compliance:requirements/nist-csf/2.0/ID.RA-10