Skip to content

Nist 800 53 Ra

FieldValue
TypeSkill Resource
Source~/.copilot/skills/security/references/ato/nist-800-53-ra.json
DescriptionNot specified

Source Content

{
"catalog_uuid": "ea7c7688-79c5-463b-a91b-0650f2d98623",
"catalog_title": "Electronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures",
"catalog_version": "5.2.0",
"group": {
"id": "ra",
"class": "family",
"title": "Risk Assessment",
"props": [
{
"name": "label",
"value": "RA"
}
],
"controls": [
{
"id": "ra-1",
"class": "SP800-53",
"title": "Policy and Procedures",
"params": [
{
"id": "ra-1_prm_1",
"props": [
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-01_odp.01"
},
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-01_odp.02"
}
],
"label": "organization-defined personnel or roles"
},
{
"id": "ra-01_odp.01",
"props": [
{
"name": "label",
"value": "RA-01_ODP[01]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the risk assessment policy is to be disseminated is/are defined;"
}
]
},
{
"id": "ra-01_odp.02",
"props": [
{
"name": "label",
"value": "RA-01_ODP[02]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the risk assessment procedures are to be disseminated is/are defined;"
}
]
},
{
"id": "ra-01_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_2"
},
{
"name": "label",
"value": "RA-01_ODP[03]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"organization-level",
"mission/business process-level",
"system-level"
]
}
},
{
"id": "ra-01_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_3"
},
{
"name": "label",
"value": "RA-01_ODP[04]",
"class": "sp800-53a"
}
],
"label": "official",
"guidelines": [
{
"prose": "an official to manage the risk assessment policy and procedures is defined;"
}
]
},
{
"id": "ra-01_odp.05",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_4"
},
{
"name": "label",
"value": "RA-01_ODP[05]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which the current risk assessment policy is reviewed and updated is defined;"
}
]
},
{
"id": "ra-01_odp.06",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_5"
},
{
"name": "label",
"value": "RA-01_ODP[06]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require the current risk assessment policy to be reviewed and updated are defined;"
}
]
},
{
"id": "ra-01_odp.07",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_6"
},
{
"name": "label",
"value": "RA-01_ODP[07]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which the current risk assessment procedures are reviewed and updated is defined;"
}
]
},
{
"id": "ra-01_odp.08",
"props": [
{
"name": "alt-identifier",
"value": "ra-1_prm_7"
},
{
"name": "label",
"value": "RA-01_ODP[08]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require risk assessment procedures to be reviewed and updated are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-01",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-1"
},
{
"name": "label",
"value": "RA-01",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#c7ac44e8-10db-4b64-b2b9-9e32ec1efed0",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#4c0ec2ee-a0d6-428a-9043-4504bc3ade6f",
"rel": "reference"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#ps-8",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "ra-1_smt",
"name": "statement",
"parts": [
{
"id": "ra-1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop, document, and disseminate to {{ insert: param, ra-1_prm_1 }}:",
"parts": [
{
"id": "ra-1_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "{{ insert: param, ra-01_odp.03 }} risk assessment policy that:",
"parts": [
{
"id": "ra-1_smt.a.1.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and"
},
{
"id": "ra-1_smt.a.1.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and"
}
]
},
{
"id": "ra-1_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures to facilitate the implementation of the risk assessment policy and the associated risk assessment controls;"
}
]
},
{
"id": "ra-1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Designate an {{ insert: param, ra-01_odp.04 }} to manage the development, documentation, and dissemination of the risk assessment policy and procedures; and"
},
{
"id": "ra-1_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Review and update the current risk assessment:",
"parts": [
{
"id": "ra-1_smt.c.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Policy {{ insert: param, ra-01_odp.05 }} and following {{ insert: param, ra-01_odp.06 }} ; and"
},
{
"id": "ra-1_smt.c.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures {{ insert: param, ra-01_odp.07 }} and following {{ insert: param, ra-01_odp.08 }}."
}
]
}
]
},
{
"id": "ra-1_gdn",
"name": "guidance",
"prose": "Risk assessment policy and procedures address the controls in the RA family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of risk assessment policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies reflecting the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to risk assessment policy and procedures include assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure."
},
{
"id": "ra-1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.[01]",
"class": "sp800-53a"
}
],
"prose": "a risk assessment policy is developed and documented;",
"links": [
{
"href": "#ra-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.[02]",
"class": "sp800-53a"
}
],
"prose": "the risk assessment policy is disseminated to {{ insert: param, ra-01_odp.01 }};",
"links": [
{
"href": "#ra-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.[03]",
"class": "sp800-53a"
}
],
"prose": "risk assessment procedures to facilitate the implementation of the risk assessment policy and associated risk assessment controls are developed and documented;",
"links": [
{
"href": "#ra-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.[04]",
"class": "sp800-53a"
}
],
"prose": "the risk assessment procedures are disseminated to {{ insert: param, ra-01_odp.02 }};",
"links": [
{
"href": "#ra-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.a.1.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.a.1.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[01]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses purpose;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[02]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses scope;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[03]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses roles;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[04]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses responsibilities;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-5",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[05]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses management commitment;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-6",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[06]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses coordination among organizational entities;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.a-7",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(a)[07]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy addresses compliance;",
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.a.1.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01a.01(b)",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.03 }} risk assessment policy is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines;",
"links": [
{
"href": "#ra-1_smt.a.1.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.a.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01b.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, ra-01_odp.04 }} is designated to manage the development, documentation, and dissemination of the risk assessment policy and procedures;",
"links": [
{
"href": "#ra-1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.c.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.c.1-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.01[01]",
"class": "sp800-53a"
}
],
"prose": "the current risk assessment policy is reviewed and updated {{ insert: param, ra-01_odp.05 }};",
"links": [
{
"href": "#ra-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.c.1-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.01[02]",
"class": "sp800-53a"
}
],
"prose": "the current risk assessment policy is reviewed and updated following {{ insert: param, ra-01_odp.06 }};",
"links": [
{
"href": "#ra-1_smt.c.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.c.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-1_obj.c.2-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.02[01]",
"class": "sp800-53a"
}
],
"prose": "the current risk assessment procedures are reviewed and updated {{ insert: param, ra-01_odp.07 }};",
"links": [
{
"href": "#ra-1_smt.c.2",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_obj.c.2-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-01c.02[02]",
"class": "sp800-53a"
}
],
"prose": "the current risk assessment procedures are reviewed and updated following {{ insert: param, ra-01_odp.08 }}.",
"links": [
{
"href": "#ra-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-01-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy and procedures\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-01-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security and privacy responsibilities"
}
]
}
]
},
{
"id": "ra-2",
"class": "SP800-53",
"title": "Security Categorization",
"props": [
{
"name": "label",
"value": "RA-02",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-2"
},
{
"name": "label",
"value": "RA-02",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#628d22a1-6a11-4784-bc59-5cd9497b5445",
"rel": "reference"
},
{
"href": "#599fb53d-5041-444e-a7fe-640d6d30ad05",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#e72fde0b-6fc2-497e-a9db-d8fce5a11b8a",
"rel": "reference"
},
{
"href": "#9be5d661-421f-41ad-854e-86f98b811891",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#4e4fbc93-333d-45e6-a875-de36b878b6b9",
"rel": "reference"
},
{
"href": "#c28ae9a8-1121-42a9-a85e-00cfcc9b9a94",
"rel": "reference"
},
{
"href": "#cm-8",
"rel": "related"
},
{
"href": "#mp-4",
"rel": "related"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#pl-10",
"rel": "related"
},
{
"href": "#pl-11",
"rel": "related"
},
{
"href": "#pm-7",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-5",
"rel": "related"
},
{
"href": "#ra-7",
"rel": "related"
},
{
"href": "#ra-8",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
},
{
"href": "#sc-7",
"rel": "related"
},
{
"href": "#sc-38",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "ra-2_smt",
"name": "statement",
"parts": [
{
"id": "ra-2_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Categorize the system and information it processes, stores, and transmits;"
},
{
"id": "ra-2_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Document the security categorization results, including supporting rationale, in the security plan for the system; and"
},
{
"id": "ra-2_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision."
}
]
},
{
"id": "ra-2_gdn",
"name": "guidance",
"prose": "Security categories describe the potential adverse impacts or negative consequences to organizational operations, organizational assets, and individuals if organizational information and systems are compromised through a loss of confidentiality, integrity, or availability. Security categorization is also a type of asset loss characterization in systems security engineering processes that is carried out throughout the system development life cycle. Organizations can use privacy risk assessments or privacy impact assessments to better understand the potential adverse effects on individuals. [CNSSI 1253](#4e4fbc93-333d-45e6-a875-de36b878b6b9) provides additional guidance on categorization for national security systems.\n\nOrganizations conduct the security categorization process as an organization-wide activity with the direct involvement of chief information officers, senior agency information security officers, senior agency officials for privacy, system owners, mission and business owners, and information owners or stewards. Organizations consider the potential adverse impacts to other organizations and, in accordance with [USA PATRIOT](#13f0c39d-eaf7-417a-baef-69a041878bb5) and Homeland Security Presidential Directives, potential national-level adverse impacts.\n\nSecurity categorization processes facilitate the development of inventories of information assets and, along with [CM-8](#cm-8) , mappings to specific system components where information is processed, stored, or transmitted. The security categorization process is revisited throughout the system development life cycle to ensure that the security categories remain accurate and relevant."
},
{
"id": "ra-2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-2_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-02a.",
"class": "sp800-53a"
}
],
"prose": "the system and the information it processes, stores, and transmits are categorized;",
"links": [
{
"href": "#ra-2_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-2_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-02b.",
"class": "sp800-53a"
}
],
"prose": "the security categorization results, including supporting rationale, are documented in the security plan for the system;",
"links": [
{
"href": "#ra-2_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "ra-2_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-02c.",
"class": "sp800-53a"
}
],
"prose": "the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.",
"links": [
{
"href": "#ra-2_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-02-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity planning policy and procedures\n\nprocedures addressing security categorization of organizational information and systems\n\nsecurity categorization documentation\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-02-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security categorization and risk assessment responsibilities\n\norganizational personnel with security and privacy responsibilities"
}
]
},
{
"id": "ra-2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-02-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for security categorization"
}
]
}
],
"controls": [
{
"id": "ra-2.1",
"class": "SP800-53-enhancement",
"title": "Impact-level Prioritization",
"props": [
{
"name": "label",
"value": "RA-02(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-2(1)"
},
{
"name": "label",
"value": "RA-02(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-02.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#ra-2",
"rel": "required"
}
],
"parts": [
{
"id": "ra-2.1_smt",
"name": "statement",
"prose": "Conduct an impact-level prioritization of organizational systems to obtain additional granularity on system impact levels."
},
{
"id": "ra-2.1_gdn",
"name": "guidance",
"prose": "Organizations apply the \"high-water mark\" concept to each system categorized in accordance with [FIPS 199](#628d22a1-6a11-4784-bc59-5cd9497b5445) , resulting in systems designated as low impact, moderate impact, or high impact. Organizations that desire additional granularity in the system impact designations for risk-based decision-making, can further partition the systems into sub-categories of the initial system categorization. For example, an impact-level prioritization on a moderate-impact system can produce three new sub-categories: low-moderate systems, moderate-moderate systems, and high-moderate systems. Impact-level prioritization and the resulting sub-categories of the system give organizations an opportunity to focus their investments related to security control selection and the tailoring of control baselines in responding to identified risks. Impact-level prioritization can also be used to determine those systems that may be of heightened interest or value to adversaries or represent a critical loss to the federal enterprise, sometimes described as high value assets. For such high value assets, organizations may be more focused on complexity, aggregation, and information exchanges. Systems with high value assets can be prioritized by partitioning high-impact systems into low-high systems, moderate-high systems, and high-high systems. Alternatively, organizations can apply the guidance in [CNSSI 1253](#4e4fbc93-333d-45e6-a875-de36b878b6b9) for security objective-related categorization."
},
{
"id": "ra-2.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-02(01)",
"class": "sp800-53a"
}
],
"prose": "an impact-level prioritization of organizational systems is conducted to obtain additional granularity on system impact levels.",
"links": [
{
"href": "#ra-2.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-2.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-02(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity and privacy planning policy and procedures\n\nprocedures addressing security categorization of organizational information and systems\n\nsecurity categorization documentation\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-2.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-02(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security categorization and risk assessment responsibilities\n\norganizational personnel with security and privacy responsibilities"
}
]
},
{
"id": "ra-2.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-02(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for security categorization"
}
]
}
]
}
]
},
{
"id": "ra-3",
"class": "SP800-53",
"title": "Risk Assessment",
"params": [
{
"id": "ra-03_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-3_prm_1"
},
{
"name": "label",
"value": "RA-03_ODP[01]",
"class": "sp800-53a"
}
],
"select": {
"choice": [
"security and privacy plans",
"risk assessment report",
"{{ insert: param, ra-03_odp.02 }} "
]
}
},
{
"id": "ra-03_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-3_prm_2"
},
{
"name": "label",
"value": "RA-03_ODP[02]",
"class": "sp800-53a"
}
],
"label": "document",
"guidelines": [
{
"prose": "a document in which risk assessment results are to be documented (if not documented in the security and privacy plans or risk assessment report) is defined (if selected);"
}
]
},
{
"id": "ra-03_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "ra-3_prm_3"
},
{
"name": "label",
"value": "RA-03_ODP[03]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency to review risk assessment results is defined;"
}
]
},
{
"id": "ra-03_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "ra-3_prm_4"
},
{
"name": "label",
"value": "RA-03_ODP[04]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom risk assessment results are to be disseminated is/are defined;"
}
]
},
{
"id": "ra-03_odp.05",
"props": [
{
"name": "alt-identifier",
"value": "ra-3_prm_5"
},
{
"name": "label",
"value": "RA-03_ODP[05]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency to update the risk assessment is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-03",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-3"
},
{
"name": "label",
"value": "RA-03",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-03"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#e8e84963-14fc-4c3a-be05-b412a5d37cd2",
"rel": "reference"
},
{
"href": "#4c501da5-9d79-4cb6-ba80-97260e1ce327",
"rel": "reference"
},
{
"href": "#98d415ca-7281-4064-9931-0c366637e324",
"rel": "reference"
},
{
"href": "#38ff38f0-1366-4f50-a4c9-26a39aacee16",
"rel": "reference"
},
{
"href": "#ca-3",
"rel": "related"
},
{
"href": "#ca-6",
"rel": "related"
},
{
"href": "#cm-4",
"rel": "related"
},
{
"href": "#cm-13",
"rel": "related"
},
{
"href": "#cp-6",
"rel": "related"
},
{
"href": "#cp-7",
"rel": "related"
},
{
"href": "#ia-8",
"rel": "related"
},
{
"href": "#ma-5",
"rel": "related"
},
{
"href": "#pe-3",
"rel": "related"
},
{
"href": "#pe-8",
"rel": "related"
},
{
"href": "#pe-18",
"rel": "related"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#pl-10",
"rel": "related"
},
{
"href": "#pl-11",
"rel": "related"
},
{
"href": "#pm-8",
"rel": "related"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#pm-28",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-7",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-5",
"rel": "related"
},
{
"href": "#ra-7",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
},
{
"href": "#sa-9",
"rel": "related"
},
{
"href": "#sc-38",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "ra-3_smt",
"name": "statement",
"parts": [
{
"id": "ra-3_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Conduct a risk assessment, including:",
"parts": [
{
"id": "ra-3_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Identifying threats to and vulnerabilities in the system;"
},
{
"id": "ra-3_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Determining the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system, the information it processes, stores, or transmits, and any related information; and"
},
{
"id": "ra-3_smt.a.3",
"name": "item",
"props": [
{
"name": "label",
"value": "3."
}
],
"prose": "Determining the likelihood and impact of adverse effects on individuals arising from the processing of personally identifiable information;"
}
]
},
{
"id": "ra-3_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Integrate risk assessment results and risk management decisions from the organization and mission or business process perspectives with system-level risk assessments;"
},
{
"id": "ra-3_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Document risk assessment results in {{ insert: param, ra-03_odp.01 }};"
},
{
"id": "ra-3_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Review risk assessment results {{ insert: param, ra-03_odp.03 }};"
},
{
"id": "ra-3_smt.e",
"name": "item",
"props": [
{
"name": "label",
"value": "e."
}
],
"prose": "Disseminate risk assessment results to {{ insert: param, ra-03_odp.04 }} ; and"
},
{
"id": "ra-3_smt.f",
"name": "item",
"props": [
{
"name": "label",
"value": "f."
}
],
"prose": "Update the risk assessment {{ insert: param, ra-03_odp.05 }} or when there are significant changes to the system, its environment of operation, or other conditions that may impact the security or privacy state of the system."
}
]
},
{
"id": "ra-3_gdn",
"name": "guidance",
"prose": "Risk assessments consider threats, vulnerabilities, likelihood, and impact to organizational operations and assets, individuals, other organizations, and the Nation. Risk assessments also consider risk from external parties, including contractors who operate systems on behalf of the organization, individuals who access organizational systems, service providers, and outsourcing entities.\n\nOrganizations can conduct risk assessments at all three levels in the risk management hierarchy (i.e., organization level, mission/business process level, or information system level) and at any stage in the system development life cycle. Risk assessments can also be conducted at various steps in the Risk Management Framework, including preparation, categorization, control selection, control implementation, control assessment, authorization, and control monitoring. Risk assessment is an ongoing activity carried out throughout the system development life cycle.\n\nRisk assessments can also address information related to the system, including system design, the intended use of the system, testing results, and supply chain-related information or artifacts. Risk assessments can play an important role in control selection processes, particularly during the application of tailoring guidance and in the earliest phases of capability determination."
},
{
"id": "ra-3_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-3_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-3_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03a.01",
"class": "sp800-53a"
}
],
"prose": "a risk assessment is conducted to identify threats to and vulnerabilities in the system;",
"links": [
{
"href": "#ra-3_smt.a.1",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.a.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03a.02",
"class": "sp800-53a"
}
],
"prose": "a risk assessment is conducted to determine the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system; the information it processes, stores, or transmits; and any related information;",
"links": [
{
"href": "#ra-3_smt.a.2",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.a.3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03a.03",
"class": "sp800-53a"
}
],
"prose": "a risk assessment is conducted to determine the likelihood and impact of adverse effects on individuals arising from the processing of personally identifiable information;",
"links": [
{
"href": "#ra-3_smt.a.3",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-3_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03b.",
"class": "sp800-53a"
}
],
"prose": "risk assessment results and risk management decisions from the organization and mission or business process perspectives are integrated with system-level risk assessments;",
"links": [
{
"href": "#ra-3_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03c.",
"class": "sp800-53a"
}
],
"prose": "risk assessment results are documented in {{ insert: param, ra-03_odp.01 }};",
"links": [
{
"href": "#ra-3_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03d.",
"class": "sp800-53a"
}
],
"prose": "risk assessment results are reviewed {{ insert: param, ra-03_odp.03 }};",
"links": [
{
"href": "#ra-3_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.e",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03e.",
"class": "sp800-53a"
}
],
"prose": "risk assessment results are disseminated to {{ insert: param, ra-03_odp.04 }};",
"links": [
{
"href": "#ra-3_smt.e",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_obj.f",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03f.",
"class": "sp800-53a"
}
],
"prose": "the risk assessment is updated {{ insert: param, ra-03_odp.05 }} or when there are significant changes to the system, its environment of operation, or other conditions that may impact the security or privacy state of the system.",
"links": [
{
"href": "#ra-3_smt.f",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-3_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-03-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nrisk assessment procedures\n\nsecurity and privacy planning policy and procedures\n\nprocedures addressing organizational assessments of risk\n\nrisk assessment\n\nrisk assessment results\n\nrisk assessment reviews\n\nrisk assessment updates\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-3_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-03-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security and privacy responsibilities"
}
]
},
{
"id": "ra-3_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-03-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for risk assessment\n\nmechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment"
}
]
}
],
"controls": [
{
"id": "ra-3.1",
"class": "SP800-53-enhancement",
"title": "Supply Chain Risk Assessment",
"params": [
{
"id": "ra-03.01_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-3.1_prm_1"
},
{
"name": "label",
"value": "RA-03(01)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "systems, system components, and system services",
"guidelines": [
{
"prose": "systems, system components, and system services to assess supply chain risks are defined;"
}
]
},
{
"id": "ra-03.01_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-3.1_prm_2"
},
{
"name": "label",
"value": "RA-03(01)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to update the supply chain risk assessment is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-03(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-3(1)"
},
{
"name": "label",
"value": "RA-03(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-03.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-3",
"rel": "required"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-9",
"rel": "related"
},
{
"href": "#pm-17",
"rel": "related"
},
{
"href": "#pm-30",
"rel": "related"
},
{
"href": "#sr-2",
"rel": "related"
}
],
"parts": [
{
"id": "ra-3.1_smt",
"name": "statement",
"parts": [
{
"id": "ra-3.1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Assess supply chain risks associated with {{ insert: param, ra-03.01_odp.01 }} ; and"
},
{
"id": "ra-3.1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Update the supply chain risk assessment {{ insert: param, ra-03.01_odp.02 }} , when there are significant changes to the relevant supply chain, or when changes to the system, environments of operation, or other conditions may necessitate a change in the supply chain."
}
]
},
{
"id": "ra-3.1_gdn",
"name": "guidance",
"prose": "Supply chain-related events include disruption, use of defective components, insertion of counterfeits, theft, malicious development practices, improper delivery practices, and insertion of malicious code. These events can have a significant impact on the confidentiality, integrity, or availability of a system and its information and, therefore, can also adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation. The supply chain-related events may be unintentional or malicious and can occur at any point during the system life cycle. An analysis of supply chain risk can help an organization identify systems or components for which additional supply chain risk mitigations are required."
},
{
"id": "ra-3.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(01)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-3.1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(01)(a)",
"class": "sp800-53a"
}
],
"prose": "supply chain risks associated with {{ insert: param, ra-03.01_odp.01 }} are assessed;",
"links": [
{
"href": "#ra-3.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(01)(b)",
"class": "sp800-53a"
}
],
"prose": "the supply chain risk assessment is updated {{ insert: param, ra-03.01_odp.02 }} , when there are significant changes to the relevant supply chain, or when changes to the system, environments of operation, or other conditions may necessitate a change in the supply chain.",
"links": [
{
"href": "#ra-3.1_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-3.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-03(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Supply chain risk management policy\n\ninventory of critical systems, system components, and system services\n\nrisk assessment policy\n\nsecurity planning policy and procedures\n\nprocedures addressing organizational assessments of supply chain risk\n\nrisk assessment\n\nrisk assessment results\n\nrisk assessment reviews\n\nrisk assessment updates\n\nacquisition policy\n\nsystem security plan\n\nsupply chain risk management plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-3.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-03(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security responsibilities\n\norganizational personnel with supply chain risk management responsibilities"
}
]
},
{
"id": "ra-3.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-03(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for risk assessment\n\nmechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the supply chain risk assessment"
}
]
}
]
},
{
"id": "ra-3.2",
"class": "SP800-53-enhancement",
"title": "Use of All-source Intelligence",
"props": [
{
"name": "label",
"value": "RA-03(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-3(2)"
},
{
"name": "label",
"value": "RA-03(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-03.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-3",
"rel": "required"
}
],
"parts": [
{
"id": "ra-3.2_smt",
"name": "statement",
"prose": "Use all-source intelligence to assist in the analysis of risk."
},
{
"id": "ra-3.2_gdn",
"name": "guidance",
"prose": "Organizations employ all-source intelligence to inform engineering, acquisition, and risk management decisions. All-source intelligence consists of information derived from all available sources, including publicly available or open-source information, measurement and signature intelligence, human intelligence, signals intelligence, and imagery intelligence. All-source intelligence is used to analyze the risk of vulnerabilities (both intentional and unintentional) from development, manufacturing, and delivery processes, people, and the environment. The risk analysis may be performed on suppliers at multiple tiers in the supply chain sufficient to manage risks. Organizations may develop agreements to share all-source intelligence information or resulting decisions with other organizations, as appropriate."
},
{
"id": "ra-3.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(02)",
"class": "sp800-53a"
}
],
"prose": "all-source intelligence is used to assist in the analysis of risk.",
"links": [
{
"href": "#ra-3.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-03(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity planning policy and procedures\n\nprocedures addressing organizational assessments of risk\n\nrisk assessment\n\nrisk assessment results\n\nrisk assessment reviews\n\nrisk assessment updates\n\nrisk intelligence reports\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-3.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-03(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-3.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-03(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for risk assessment\n\nmechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment"
}
]
}
]
},
{
"id": "ra-3.3",
"class": "SP800-53-enhancement",
"title": "Dynamic Threat Awareness",
"params": [
{
"id": "ra-03.03_odp",
"props": [
{
"name": "alt-identifier",
"value": "ra-3.3_prm_1"
},
{
"name": "label",
"value": "RA-03(03)_ODP",
"class": "sp800-53a"
}
],
"label": "means",
"guidelines": [
{
"prose": "means to determine the current cyber threat environment on an ongoing basis;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-03(03)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-3(3)"
},
{
"name": "label",
"value": "RA-03(03)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-03.03"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-3",
"rel": "required"
},
{
"href": "#at-2",
"rel": "related"
}
],
"parts": [
{
"id": "ra-3.3_smt",
"name": "statement",
"prose": "Determine the current cyber threat environment on an ongoing basis using {{ insert: param, ra-03.03_odp }}."
},
{
"id": "ra-3.3_gdn",
"name": "guidance",
"prose": "The threat awareness information that is gathered feeds into the organization\u2019s information security operations to ensure that procedures are updated in response to the changing threat environment. For example, at higher threat levels, organizations may change the privilege or authentication thresholds required to perform certain operations."
},
{
"id": "ra-3.3_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(03)",
"class": "sp800-53a"
}
],
"prose": "the current cyber threat environment is determined on an ongoing basis using {{ insert: param, ra-03.03_odp }}.",
"links": [
{
"href": "#ra-3.3_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.3_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-03(03)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity planning policy and procedures\n\nprocedures addressing organizational assessments of risk\n\nrisk assessment\n\nrisk assessment results\n\nrisk assessment reviews\n\nrisk assessment updates\n\nrisk reports\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-3.3_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-03(03)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-3.3_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-03(03)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for risk assessment\n\nmechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment"
}
]
}
]
},
{
"id": "ra-3.4",
"class": "SP800-53-enhancement",
"title": "Predictive Cyber Analytics",
"params": [
{
"id": "ra-3.4_prm_2",
"props": [
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-03.04_odp.01"
},
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-03.04_odp.03"
}
],
"label": "organization-defined advanced automation and analytics capabilities"
},
{
"id": "ra-03.04_odp.01",
"props": [
{
"name": "label",
"value": "RA-03(04)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "advanced automation capabilities",
"guidelines": [
{
"prose": "advanced automation capabilities to predict and identify risks are defined;"
}
]
},
{
"id": "ra-03.04_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-3.4_prm_1"
},
{
"name": "label",
"value": "RA-03(04)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "systems or system components",
"guidelines": [
{
"prose": "systems or system components where advanced automation and analytics capabilities are to be employed are defined;"
}
]
},
{
"id": "ra-03.04_odp.03",
"props": [
{
"name": "label",
"value": "RA-03(04)_ODP[03]",
"class": "sp800-53a"
}
],
"label": "advanced analytics capabilities",
"guidelines": [
{
"prose": "advanced analytics capabilities to predict and identify risks are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-03(04)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-3(4)"
},
{
"name": "label",
"value": "RA-03(04)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-03.04"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-3",
"rel": "required"
}
],
"parts": [
{
"id": "ra-3.4_smt",
"name": "statement",
"prose": "Employ the following advanced automation and analytics capabilities to predict and identify risks to {{ insert: param, ra-03.04_odp.02 }}: {{ insert: param, ra-3.4_prm_2 }}."
},
{
"id": "ra-3.4_gdn",
"name": "guidance",
"prose": "A properly resourced Security Operations Center (SOC) or Computer Incident Response Team (CIRT) may be overwhelmed by the volume of information generated by the proliferation of security tools and appliances unless it employs advanced automation and analytics to analyze the data. Advanced automation and analytics capabilities are typically supported by artificial intelligence concepts, including machine learning. Examples include Automated Threat Discovery and Response (which includes broad-based collection, context-based analysis, and adaptive response capabilities), automated workflow operations, and machine assisted decision tools. Note, however, that sophisticated adversaries may be able to extract information related to analytic parameters and retrain the machine learning to classify malicious activity as benign. Accordingly, machine learning is augmented by human monitoring to ensure that sophisticated adversaries are not able to conceal their activities."
},
{
"id": "ra-3.4_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(04)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-3.4_obj-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(04)[01]",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, ra-03.04_odp.01 }} are employed to predict and identify risks to {{ insert: param, ra-03.04_odp.02 }};",
"links": [
{
"href": "#ra-3.4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.4_obj-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-03(04)[02]",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, ra-03.04_odp.03 }} are employed to predict and identify risks to {{ insert: param, ra-03.04_odp.02 }}.",
"links": [
{
"href": "#ra-3.4_smt",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-3.4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-3.4_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-03(04)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity planning policy and procedures\n\nprocedures addressing organizational assessments of risk\n\nrisk assessment\n\nrisk assessment results\n\nrisk assessment reviews\n\nrisk assessment updates\n\nrisk reports\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-3.4_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-03(04)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-3.4_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-03(04)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for risk assessment\n\nmechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment"
}
]
}
]
}
]
},
{
"id": "ra-4",
"class": "SP800-53",
"title": "Risk Assessment Update",
"props": [
{
"name": "label",
"value": "RA-04",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-4"
},
{
"name": "label",
"value": "RA-04",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-04"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#ra-3",
"rel": "incorporated-into"
}
]
},
{
"id": "ra-5",
"class": "SP800-53",
"title": "Vulnerability Monitoring and Scanning",
"params": [
{
"id": "ra-5_prm_1",
"props": [
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-05_odp.01"
},
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "ra-05_odp.02"
}
],
"label": "organization-defined frequency and/or randomly in accordance with organization-defined process"
},
{
"id": "ra-05_odp.01",
"props": [
{
"name": "label",
"value": "RA-05_ODP[01]",
"class": "sp800-53a"
}
],
"label": "frequency and/or randomly in accordance with organization-defined process",
"guidelines": [
{
"prose": "frequency for monitoring systems and hosted applications for vulnerabilities is defined;"
}
]
},
{
"id": "ra-05_odp.02",
"props": [
{
"name": "label",
"value": "RA-05_ODP[02]",
"class": "sp800-53a"
}
],
"label": "frequency and/or randomly in accordance with organization-defined process",
"guidelines": [
{
"prose": "frequency for scanning systems and hosted applications for vulnerabilities is defined;"
}
]
},
{
"id": "ra-05_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "ra-5_prm_2"
},
{
"name": "label",
"value": "RA-05_ODP[03]",
"class": "sp800-53a"
}
],
"label": "response times",
"guidelines": [
{
"prose": "response times to remediate legitimate vulnerabilities in accordance with an organizational assessment of risk are defined;"
}
]
},
{
"id": "ra-05_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "ra-5_prm_3"
},
{
"name": "label",
"value": "RA-05_ODP[04]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles with whom information obtained from the vulnerability scanning process and control assessments is to be shared;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5"
},
{
"name": "label",
"value": "RA-05",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#8df72805-2e5c-4731-a73e-81db0f0318d0",
"rel": "reference"
},
{
"href": "#155f941a-cba9-4afd-9ca6-5d040d697ba9",
"rel": "reference"
},
{
"href": "#a21aef46-7330-48a0-b2e1-c5bb8b2dd11d",
"rel": "reference"
},
{
"href": "#4895b4cd-34c5-4667-bf8a-27d443c12047",
"rel": "reference"
},
{
"href": "#122177fa-c4ed-485d-8345-3082c0fb9a06",
"rel": "reference"
},
{
"href": "#8016d2ed-d30f-4416-9c45-0f42c7aa3232",
"rel": "reference"
},
{
"href": "#aa5d04e0-6090-4e17-84d4-b9963d55fc2c",
"rel": "reference"
},
{
"href": "#d2ebec9b-f868-4ee1-a2bd-0b2282aed248",
"rel": "reference"
},
{
"href": "#4c501da5-9d79-4cb6-ba80-97260e1ce327",
"rel": "reference"
},
{
"href": "#ca-2",
"rel": "related"
},
{
"href": "#ca-7",
"rel": "related"
},
{
"href": "#ca-8",
"rel": "related"
},
{
"href": "#cm-2",
"rel": "related"
},
{
"href": "#cm-4",
"rel": "related"
},
{
"href": "#cm-6",
"rel": "related"
},
{
"href": "#cm-8",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#sa-11",
"rel": "related"
},
{
"href": "#sa-15",
"rel": "related"
},
{
"href": "#sc-38",
"rel": "related"
},
{
"href": "#si-2",
"rel": "related"
},
{
"href": "#si-3",
"rel": "related"
},
{
"href": "#si-4",
"rel": "related"
},
{
"href": "#si-7",
"rel": "related"
},
{
"href": "#sr-11",
"rel": "related"
}
],
"parts": [
{
"id": "ra-5_smt",
"name": "statement",
"parts": [
{
"id": "ra-5_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Monitor and scan for vulnerabilities in the system and hosted applications {{ insert: param, ra-5_prm_1 }} and when new vulnerabilities potentially affecting the system are identified and reported;"
},
{
"id": "ra-5_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for:",
"parts": [
{
"id": "ra-5_smt.b.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Enumerating platforms, software flaws, and improper configurations;"
},
{
"id": "ra-5_smt.b.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Formatting checklists and test procedures; and"
},
{
"id": "ra-5_smt.b.3",
"name": "item",
"props": [
{
"name": "label",
"value": "3."
}
],
"prose": "Measuring vulnerability impact;"
}
]
},
{
"id": "ra-5_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Analyze vulnerability scan reports and results from vulnerability monitoring;"
},
{
"id": "ra-5_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Remediate legitimate vulnerabilities {{ insert: param, ra-05_odp.03 }} in accordance with an organizational assessment of risk;"
},
{
"id": "ra-5_smt.e",
"name": "item",
"props": [
{
"name": "label",
"value": "e."
}
],
"prose": "Share information obtained from the vulnerability monitoring process and control assessments with {{ insert: param, ra-05_odp.04 }} to help eliminate similar vulnerabilities in other systems; and"
},
{
"id": "ra-5_smt.f",
"name": "item",
"props": [
{
"name": "label",
"value": "f."
}
],
"prose": "Employ vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned."
}
]
},
{
"id": "ra-5_gdn",
"name": "guidance",
"prose": "Security categorization of information and systems guides the frequency and comprehensiveness of vulnerability monitoring (including scans). Organizations determine the required vulnerability monitoring for system components, ensuring that the potential sources of vulnerabilities\u2014such as infrastructure components (e.g., switches, routers, guards, sensors), networked printers, scanners, and copiers\u2014are not overlooked. The capability to readily update vulnerability monitoring tools as new vulnerabilities are discovered and announced and as new scanning methods are developed helps to ensure that new vulnerabilities are not missed by employed vulnerability monitoring tools. The vulnerability monitoring tool update process helps to ensure that potential vulnerabilities in the system are identified and addressed as quickly as possible. Vulnerability monitoring and analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches. Organizations can use these analysis approaches in source code reviews and in a variety of tools, including web-based application scanners, static analysis tools, and binary analyzers.\n\nVulnerability monitoring includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for flow control mechanisms that are improperly configured or operating incorrectly. Vulnerability monitoring may also include continuous vulnerability monitoring tools that use instrumentation to continuously analyze components. Instrumentation-based tools may improve accuracy and may be run throughout an organization without scanning. Vulnerability monitoring tools that facilitate interoperability include tools that are Security Content Automated Protocol (SCAP)-validated. Thus, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention and that employ the Open Vulnerability Assessment Language (OVAL) to determine the presence of vulnerabilities. Sources for vulnerability information include the Common Weakness Enumeration (CWE) listing and the National Vulnerability Database (NVD). Control assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan. Organizations also consider using scanning tools that express vulnerability impact by the Common Vulnerability Scoring System (CVSS).\n\nVulnerability monitoring includes a channel and process for receiving reports of security vulnerabilities from the public at-large. Vulnerability disclosure programs can be as simple as publishing a monitored email address or web form that can receive reports, including notification authorizing good-faith research and disclosure of security vulnerabilities. Organizations generally expect that such research is happening with or without their authorization and can use public vulnerability disclosure channels to increase the likelihood that discovered vulnerabilities are reported directly to the organization for remediation.\n\nOrganizations may also employ the use of financial incentives (also known as \"bug bounties\" ) to further encourage external security researchers to report discovered vulnerabilities. Bug bounty programs can be tailored to the organization\u2019s needs. Bounties can be operated indefinitely or over a defined period of time and can be offered to the general public or to a curated group. Organizations may run public and private bounties simultaneously and could choose to offer partially credentialed access to certain participants in order to evaluate security vulnerabilities from privileged vantage points."
},
{
"id": "ra-5_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-5_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-5_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05a.[01]",
"class": "sp800-53a"
}
],
"prose": "systems and hosted applications are monitored for vulnerabilities {{ insert: param, ra-05_odp.01 }} and when new vulnerabilities potentially affecting the system are identified and reported;",
"links": [
{
"href": "#ra-5_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05a.[02]",
"class": "sp800-53a"
}
],
"prose": "systems and hosted applications are scanned for vulnerabilities {{ insert: param, ra-05_odp.02 }} and when new vulnerabilities potentially affecting the system are identified and reported;",
"links": [
{
"href": "#ra-5_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-5_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05b.",
"class": "sp800-53a"
}
],
"prose": "vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools;",
"parts": [
{
"id": "ra-5_obj.b.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05b.01",
"class": "sp800-53a"
}
],
"prose": "vulnerability monitoring tools and techniques are employed to automate parts of the vulnerability management process by using standards for enumerating platforms, software flaws, and improper configurations;",
"links": [
{
"href": "#ra-5_smt.b.1",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.b.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05b.02",
"class": "sp800-53a"
}
],
"prose": "vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for formatting checklists and test procedures;",
"links": [
{
"href": "#ra-5_smt.b.2",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.b.3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05b.03",
"class": "sp800-53a"
}
],
"prose": "vulnerability monitoring tools and techniques are employed to facilitate interoperability among tools and to automate parts of the vulnerability management process by using standards for measuring vulnerability impact;",
"links": [
{
"href": "#ra-5_smt.b.3",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-5_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05c.",
"class": "sp800-53a"
}
],
"prose": "vulnerability scan reports and results from vulnerability monitoring are analyzed;",
"links": [
{
"href": "#ra-5_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05d.",
"class": "sp800-53a"
}
],
"prose": "legitimate vulnerabilities are remediated {{ insert: param, ra-05_odp.03 }} in accordance with an organizational assessment of risk;",
"links": [
{
"href": "#ra-5_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.e",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05e.",
"class": "sp800-53a"
}
],
"prose": "information obtained from the vulnerability monitoring process and control assessments is shared with {{ insert: param, ra-05_odp.04 }} to help eliminate similar vulnerabilities in other systems;",
"links": [
{
"href": "#ra-5_smt.e",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_obj.f",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05f.",
"class": "sp800-53a"
}
],
"prose": "vulnerability monitoring tools that include the capability to readily update the vulnerabilities to be scanned are employed.",
"links": [
{
"href": "#ra-5_smt.f",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-5_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\nrisk assessment\n\nassessment report\n\nvulnerability scanning tools and associated configuration documentation\n\nvulnerability scanning results\n\npatch and vulnerability management records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with risk assessment, control assessment, and vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with vulnerability remediation responsibilities\n\norganizational personnel with security responsibilities\n\nsystem/network administrators"
}
]
},
{
"id": "ra-5_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning, analysis, remediation, and information sharing\n\nmechanisms supporting and/or implementing vulnerability scanning, analysis, remediation, and information sharing"
}
]
}
],
"controls": [
{
"id": "ra-5.1",
"class": "SP800-53-enhancement",
"title": "Update Tool Capability",
"props": [
{
"name": "label",
"value": "RA-05(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(1)"
},
{
"name": "label",
"value": "RA-05(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.01"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#ra-5",
"rel": "incorporated-into"
}
]
},
{
"id": "ra-5.2",
"class": "SP800-53-enhancement",
"title": "Update Vulnerabilities to Be Scanned",
"params": [
{
"id": "ra-05.02_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.2_prm_1"
},
{
"name": "label",
"value": "RA-05(02)_ODP[01]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"{{ insert: param, ra-05.02_odp.02 }} ",
"prior to a new scan",
"when new vulnerabilities are identified and reported"
]
}
},
{
"id": "ra-05.02_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.2_prm_2"
},
{
"name": "label",
"value": "RA-05(02)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency for updating the system vulnerabilities to be scanned is defined (if selected);"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(2)"
},
{
"name": "label",
"value": "RA-05(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
},
{
"href": "#si-5",
"rel": "related"
}
],
"parts": [
{
"id": "ra-5.2_smt",
"name": "statement",
"prose": "Update the system vulnerabilities to be scanned {{ insert: param, ra-05.02_odp.01 }}."
},
{
"id": "ra-5.2_gdn",
"name": "guidance",
"prose": "Due to the complexity of modern software, systems, and other factors, new vulnerabilities are discovered on a regular basis. It is important that newly discovered vulnerabilities are added to the list of vulnerabilities to be scanned to ensure that the organization can take steps to mitigate those vulnerabilities in a timely manner."
},
{
"id": "ra-5.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(02)",
"class": "sp800-53a"
}
],
"prose": "the system vulnerabilities to be scanned are updated {{ insert: param, ra-05.02_odp.01 }}.",
"links": [
{
"href": "#ra-5.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Procedures addressing vulnerability scanning\n\nassessment report\n\nvulnerability scanning tools and associated configuration documentation\n\nvulnerability scanning results\n\npatch and vulnerability management records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with security responsibilities\n\nsystem/network administrators"
}
]
},
{
"id": "ra-5.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\nmechanisms/tools supporting and/or implementing vulnerability scanning"
}
]
}
]
},
{
"id": "ra-5.3",
"class": "SP800-53-enhancement",
"title": "Breadth and Depth of Coverage",
"props": [
{
"name": "label",
"value": "RA-05(03)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(3)"
},
{
"name": "label",
"value": "RA-05(03)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.03"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
}
],
"parts": [
{
"id": "ra-5.3_smt",
"name": "statement",
"prose": "Define the breadth and depth of vulnerability scanning coverage."
},
{
"id": "ra-5.3_gdn",
"name": "guidance",
"prose": "The breadth of vulnerability scanning coverage can be expressed as a percentage of components within the system, by the particular types of systems, by the criticality of systems, or by the number of vulnerabilities to be checked. Conversely, the depth of vulnerability scanning coverage can be expressed as the level of the system design that the organization intends to monitor (e.g., component, module, subsystem, element). Organizations can determine the sufficiency of vulnerability scanning coverage with regard to its risk tolerance and other factors. Scanning tools and how the tools are configured may affect the depth and coverage. Multiple scanning tools may be needed to achieve the desired depth and coverage. [SP 800-53A](#a21aef46-7330-48a0-b2e1-c5bb8b2dd11d) provides additional information on the breadth and depth of coverage."
},
{
"id": "ra-5.3_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(03)",
"class": "sp800-53a"
}
],
"prose": "the breadth and depth of vulnerability scanning coverage are defined.",
"links": [
{
"href": "#ra-5.3_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.3_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(03)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Procedures addressing vulnerability scanning\n\nassessment report\n\nvulnerability scanning tools and associated configuration documentation\n\nvulnerability scanning results\n\npatch and vulnerability management records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.3_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(03)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.3_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(03)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\nmechanisms/tools supporting and/or implementing vulnerability scanning"
}
]
}
]
},
{
"id": "ra-5.4",
"class": "SP800-53-enhancement",
"title": "Discoverable Information",
"params": [
{
"id": "ra-05.04_odp",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.4_prm_1"
},
{
"name": "label",
"value": "RA-05(04)_ODP",
"class": "sp800-53a"
}
],
"label": "corrective actions",
"guidelines": [
{
"prose": "corrective actions to be taken if information about the system is discoverable are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05(04)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(4)"
},
{
"name": "label",
"value": "RA-05(04)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.04"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
},
{
"href": "#au-13",
"rel": "related"
},
{
"href": "#sc-26",
"rel": "related"
}
],
"parts": [
{
"id": "ra-5.4_smt",
"name": "statement",
"prose": "Determine information about the system that is discoverable and take {{ insert: param, ra-05.04_odp }}."
},
{
"id": "ra-5.4_gdn",
"name": "guidance",
"prose": "Discoverable information includes information that adversaries could obtain without compromising or breaching the system, such as by collecting information that the system is exposing or by conducting extensive web searches. Corrective actions include notifying appropriate organizational personnel, removing designated information, or changing the system to make the designated information less relevant or attractive to adversaries. This enhancement excludes intentionally discoverable information that may be part of a decoy capability (e.g., honeypots, honeynets, or deception nets) deployed by the organization."
},
{
"id": "ra-5.4_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(04)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-5.4_obj-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(04)[01]",
"class": "sp800-53a"
}
],
"prose": "information about the system is discoverable;",
"links": [
{
"href": "#ra-5.4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.4_obj-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(04)[02]",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, ra-05.04_odp }} are taken when information about the system is confirmed as discoverable.",
"links": [
{
"href": "#ra-5.4_smt",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-5.4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.4_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(04)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Procedures addressing vulnerability scanning\n\nassessment report\n\npenetration test results\n\nvulnerability scanning results\n\nrisk assessment report\n\nrecords of corrective actions taken\n\nincident response records\n\naudit records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.4_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(04)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning and/or penetration testing responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel responsible for risk response\n\norganizational personnel responsible for incident management and response\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.4_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(04)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\norganizational processes for risk response\n\norganizational processes for incident management and response\n\nmechanisms/tools supporting and/or implementing vulnerability scanning\n\nmechanisms supporting and/or implementing risk response\n\nmechanisms supporting and/or implementing incident management and response"
}
]
}
]
},
{
"id": "ra-5.5",
"class": "SP800-53-enhancement",
"title": "Privileged Access",
"params": [
{
"id": "ra-05.05_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.5_prm_1"
},
{
"name": "label",
"value": "RA-05(05)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "system components",
"guidelines": [
{
"prose": "system components to which privileged access is authorized for selected vulnerability scanning activities are defined;"
}
]
},
{
"id": "ra-05.05_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.5_prm_2"
},
{
"name": "label",
"value": "RA-05(05)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "vulnerability scanning activities",
"guidelines": [
{
"prose": "vulnerability scanning activities selected for privileged access authorization to system components are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05(05)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(5)"
},
{
"name": "label",
"value": "RA-05(05)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.05"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
}
],
"parts": [
{
"id": "ra-5.5_smt",
"name": "statement",
"prose": "Implement privileged access authorization to {{ insert: param, ra-05.05_odp.01 }} for {{ insert: param, ra-05.05_odp.02 }}."
},
{
"id": "ra-5.5_gdn",
"name": "guidance",
"prose": "In certain situations, the nature of the vulnerability scanning may be more intrusive, or the system component that is the subject of the scanning may contain classified or controlled unclassified information, such as personally identifiable information. Privileged access authorization to selected system components facilitates more thorough vulnerability scanning and protects the sensitive nature of such scanning."
},
{
"id": "ra-5.5_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(05)",
"class": "sp800-53a"
}
],
"prose": "privileged access authorization is implemented to {{ insert: param, ra-05.05_odp.01 }} for {{ insert: param, ra-05.05_odp.02 }}.",
"links": [
{
"href": "#ra-5.5_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.5_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(05)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\nsystem design documentation\n\nsystem configuration settings and associated documentation\n\nlist of system components for vulnerability scanning\n\npersonnel access authorization list\n\nauthorization credentials\n\naccess authorization records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.5_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(05)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\nsystem/network administrators\n\norganizational personnel responsible for access control to the system\n\norganizational personnel responsible for configuration management of the system\n\nsystem developers\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.5_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(05)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\norganizational processes for access control\n\nmechanisms supporting and/or implementing access control\n\nmechanisms/tools supporting and/or implementing vulnerability scanning"
}
]
}
]
},
{
"id": "ra-5.6",
"class": "SP800-53-enhancement",
"title": "Automated Trend Analyses",
"params": [
{
"id": "ra-05.06_odp",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.6_prm_1"
},
{
"name": "label",
"value": "RA-05(06)_ODP",
"class": "sp800-53a"
}
],
"label": "automated mechanisms",
"guidelines": [
{
"prose": "automated mechanisms to compare the results of multiple vulnerability scans are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05(06)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(6)"
},
{
"name": "label",
"value": "RA-05(06)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.06"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
}
],
"parts": [
{
"id": "ra-5.6_smt",
"name": "statement",
"prose": "Compare the results of multiple vulnerability scans using {{ insert: param, ra-05.06_odp }}."
},
{
"id": "ra-5.6_gdn",
"name": "guidance",
"prose": "Using automated mechanisms to analyze multiple vulnerability scans over time can help determine trends in system vulnerabilities and identify patterns of attack."
},
{
"id": "ra-5.6_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(06)",
"class": "sp800-53a"
}
],
"prose": "the results of multiple vulnerability scans are compared using {{ insert: param, ra-05.06_odp }}.",
"links": [
{
"href": "#ra-5.6_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.6_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(06)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\nsystem design documentation\n\nvulnerability scanning tools and techniques documentation\n\nvulnerability scanning results\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.6_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(06)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.6_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(06)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\nautomated mechanisms/tools supporting and/or implementing vulnerability scanning\n\nautomated mechanisms supporting and/or implementing trend analysis of vulnerability scan results"
}
]
}
]
},
{
"id": "ra-5.7",
"class": "SP800-53-enhancement",
"title": "Automated Detection and Notification of Unauthorized Components",
"props": [
{
"name": "label",
"value": "RA-05(07)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(7)"
},
{
"name": "label",
"value": "RA-05(07)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.07"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#cm-8",
"rel": "incorporated-into"
}
]
},
{
"id": "ra-5.8",
"class": "SP800-53-enhancement",
"title": "Review Historic Audit Logs",
"params": [
{
"id": "ra-05.08_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.8_prm_1"
},
{
"name": "label",
"value": "RA-05(08)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "system",
"guidelines": [
{
"prose": "a system whose historic audit logs are to be reviewed is defined;"
}
]
},
{
"id": "ra-05.08_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-5.8_prm_2"
},
{
"name": "label",
"value": "RA-05(08)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "time period",
"guidelines": [
{
"prose": "a time period for a potential previous exploit of a system is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-05(08)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(8)"
},
{
"name": "label",
"value": "RA-05(08)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.08"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
},
{
"href": "#au-6",
"rel": "related"
},
{
"href": "#au-11",
"rel": "related"
}
],
"parts": [
{
"id": "ra-5.8_smt",
"name": "statement",
"prose": "Review historic audit logs to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within an {{ insert: param, ra-05.08_odp.02 }}."
},
{
"id": "ra-5.8_gdn",
"name": "guidance",
"prose": "Reviewing historic audit logs to determine if a recently detected vulnerability in a system has been previously exploited by an adversary can provide important information for forensic analyses. Such analyses can help identify, for example, the extent of a previous intrusion, the trade craft employed during the attack, organizational information exfiltrated or modified, mission or business capabilities affected, and the duration of the attack."
},
{
"id": "ra-5.8_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(08)",
"class": "sp800-53a"
}
],
"prose": "historic audit logs are reviewed to determine if a vulnerability identified in a {{ insert: param, ra-05.08_odp.01 }} has been previously exploited within {{ insert: param, ra-05.08_odp.02 }}.",
"links": [
{
"href": "#ra-5.8_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.8_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(08)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\naudit logs\n\nrecords of audit log reviews\n\nvulnerability scanning results\n\npatch and vulnerability management records\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.8_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(08)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with audit record review responsibilities\n\nsystem/network administrators\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.8_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(08)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\norganizational process for audit record review and response\n\nmechanisms/tools supporting and/or implementing vulnerability scanning\n\nmechanisms supporting and/or implementing audit record review"
}
]
}
]
},
{
"id": "ra-5.9",
"class": "SP800-53-enhancement",
"title": "Penetration Testing and Analyses",
"props": [
{
"name": "label",
"value": "RA-05(09)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(9)"
},
{
"name": "label",
"value": "RA-05(09)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.09"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#ca-8",
"rel": "incorporated-into"
}
]
},
{
"id": "ra-5.10",
"class": "SP800-53-enhancement",
"title": "Correlate Scanning Information",
"props": [
{
"name": "label",
"value": "RA-05(10)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(10)"
},
{
"name": "label",
"value": "RA-05(10)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.10"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
}
],
"parts": [
{
"id": "ra-5.10_smt",
"name": "statement",
"prose": "Correlate the output from vulnerability scanning tools to determine the presence of multi-vulnerability and multi-hop attack vectors."
},
{
"id": "ra-5.10_gdn",
"name": "guidance",
"prose": "An attack vector is a path or means by which an adversary can gain access to a system in order to deliver malicious code or exfiltrate information. Organizations can use attack trees to show how hostile activities by adversaries interact and combine to produce adverse impacts or negative consequences to systems and organizations. Such information, together with correlated data from vulnerability scanning tools, can provide greater clarity regarding multi-vulnerability and multi-hop attack vectors. The correlation of vulnerability scanning information is especially important when organizations are transitioning from older technologies to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). During such transitions, some system components may inadvertently be unmanaged and create opportunities for adversary exploitation."
},
{
"id": "ra-5.10_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(10)",
"class": "sp800-53a"
}
],
"prose": "the output from vulnerability scanning tools is correlated to determine the presence of multi-vulnerability and multi-hop attack vectors.",
"links": [
{
"href": "#ra-5.10_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.10_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(10)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\nrisk assessment\n\nvulnerability scanning tools and techniques documentation\n\nvulnerability scanning results\n\nvulnerability management records\n\naudit records\n\nevent/vulnerability correlation logs\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.10_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(10)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.10_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(10)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\nmechanisms/tools supporting and/or implementing vulnerability scanning\n\nmechanisms implementing the correlation of vulnerability scan results"
}
]
}
]
},
{
"id": "ra-5.11",
"class": "SP800-53-enhancement",
"title": "Public Disclosure Program",
"props": [
{
"name": "label",
"value": "RA-05(11)",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-5(11)"
},
{
"name": "label",
"value": "RA-05(11)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-05.11"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#ra-5",
"rel": "required"
}
],
"parts": [
{
"id": "ra-5.11_smt",
"name": "statement",
"prose": "Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components."
},
{
"id": "ra-5.11_gdn",
"name": "guidance",
"prose": "The reporting channel is publicly discoverable and contains clear language authorizing good-faith research and the disclosure of vulnerabilities to the organization. The organization does not condition its authorization on an expectation of indefinite non-disclosure to the public by the reporting entity but may request a specific time period to properly remediate the vulnerability."
},
{
"id": "ra-5.11_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-05(11)",
"class": "sp800-53a"
}
],
"prose": "a public reporting channel is established for receiving reports of vulnerabilities in organizational systems and system components.",
"links": [
{
"href": "#ra-5.11_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-5.11_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-05(11)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing vulnerability scanning\n\nrisk assessment\n\nvulnerability scanning tools and techniques documentation\n\nvulnerability scanning results\n\nvulnerability management records\n\naudit records\n\npublic reporting channel\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-5.11_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-05(11)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with vulnerability scanning responsibilities\n\norganizational personnel with vulnerability scan analysis responsibilities\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-5.11_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-05(11)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for vulnerability scanning\n\nmechanisms/tools supporting and/or implementing vulnerability scanning\n\nmechanisms implementing the public reporting of vulnerabilities"
}
]
}
]
}
]
},
{
"id": "ra-6",
"class": "SP800-53",
"title": "Technical Surveillance Countermeasures Survey",
"params": [
{
"id": "ra-06_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-6_prm_1"
},
{
"name": "label",
"value": "RA-06_ODP[01]",
"class": "sp800-53a"
}
],
"label": "locations",
"guidelines": [
{
"prose": "locations to employ technical surveillance countermeasure surveys are defined;"
}
]
},
{
"id": "ra-06_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-6_prm_2"
},
{
"name": "label",
"value": "RA-06_ODP[02]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"{{ insert: param, ra-06_odp.03 }} ",
"when {{ insert: param, ra-06_odp.04 }} "
]
}
},
{
"id": "ra-06_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "ra-6_prm_3"
},
{
"name": "label",
"value": "RA-06_ODP[03]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to employ technical surveillance countermeasure surveys is defined (if selected);"
}
]
},
{
"id": "ra-06_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "ra-6_prm_4"
},
{
"name": "label",
"value": "RA-06_ODP[04]",
"class": "sp800-53a"
}
],
"label": "events or indicators",
"guidelines": [
{
"prose": "events or indicators which, if they occur, trigger a technical surveillance countermeasures survey are defined (if selected);"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-06",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-6"
},
{
"name": "label",
"value": "RA-06",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-06"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"parts": [
{
"id": "ra-6_smt",
"name": "statement",
"prose": "Employ a technical surveillance countermeasures survey at {{ insert: param, ra-06_odp.01 }} {{ insert: param, ra-06_odp.02 }}."
},
{
"id": "ra-6_gdn",
"name": "guidance",
"prose": "A technical surveillance countermeasures survey is a service provided by qualified personnel to detect the presence of technical surveillance devices and hazards and to identify technical security weaknesses that could be used in the conduct of a technical penetration of the surveyed facility. Technical surveillance countermeasures surveys also provide evaluations of the technical security posture of organizations and facilities and include visual, electronic, and physical examinations of surveyed facilities, internally and externally. The surveys also provide useful input for risk assessments and information regarding organizational exposure to potential adversaries."
},
{
"id": "ra-6_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-06",
"class": "sp800-53a"
}
],
"prose": "a technical surveillance countermeasures survey is employed at {{ insert: param, ra-06_odp.01 }} {{ insert: param, ra-06_odp.02 }}.",
"links": [
{
"href": "#ra-6_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-6_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-06-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nprocedures addressing technical surveillance countermeasures surveys\n\naudit records/event logs\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-6_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-06-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with technical surveillance countermeasures surveys responsibilities\n\nsystem/network administrators\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-6_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-06-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for technical surveillance countermeasures surveys\n\nmechanisms/tools supporting and/or implementing technical surveillance countermeasure surveys"
}
]
}
]
},
{
"id": "ra-7",
"class": "SP800-53",
"title": "Risk Response",
"props": [
{
"name": "label",
"value": "RA-07",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-7"
},
{
"name": "label",
"value": "RA-07",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-07"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#628d22a1-6a11-4784-bc59-5cd9497b5445",
"rel": "reference"
},
{
"href": "#599fb53d-5041-444e-a7fe-640d6d30ad05",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#ca-5",
"rel": "related"
},
{
"href": "#ir-9",
"rel": "related"
},
{
"href": "#pm-4",
"rel": "related"
},
{
"href": "#pm-28",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#sr-2",
"rel": "related"
}
],
"parts": [
{
"id": "ra-7_smt",
"name": "statement",
"prose": "Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance."
},
{
"id": "ra-7_gdn",
"name": "guidance",
"prose": "Organizations have many options for responding to risk including mitigating risk by implementing new controls or strengthening existing controls, accepting risk with appropriate justification or rationale, sharing or transferring risk, or avoiding risk. The risk tolerance of the organization influences risk response decisions and actions. Risk response addresses the need to determine an appropriate response to risk before generating a plan of action and milestones entry. For example, the response may be to accept risk or reject risk, or it may be possible to mitigate the risk immediately so that a plan of action and milestones entry is not needed. However, if the risk response is to mitigate the risk, and the mitigation cannot be completed immediately, a plan of action and milestones entry is generated."
},
{
"id": "ra-7_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-07",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-7_obj-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-07[01]",
"class": "sp800-53a"
}
],
"prose": "findings from security assessments are responded to in accordance with organizational risk tolerance;",
"links": [
{
"href": "#ra-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-7_obj-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-07[02]",
"class": "sp800-53a"
}
],
"prose": "findings from privacy assessments are responded to in accordance with organizational risk tolerance;",
"links": [
{
"href": "#ra-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-7_obj-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-07[03]",
"class": "sp800-53a"
}
],
"prose": "findings from monitoring are responded to in accordance with organizational risk tolerance;",
"links": [
{
"href": "#ra-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-7_obj-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-07[04]",
"class": "sp800-53a"
}
],
"prose": "findings from audits are responded to in accordance with organizational risk tolerance.",
"links": [
{
"href": "#ra-7_smt",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-7_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-07-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nassessment reports\n\naudit records/event logs\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-7_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-07-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with assessment and auditing responsibilities\n\nsystem/network administrators\n\norganizational personnel with security and privacy responsibilities"
}
]
},
{
"id": "ra-7_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-07-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for assessments and audits\n\nmechanisms/tools supporting and/or implementing assessments and auditing"
}
]
}
]
},
{
"id": "ra-8",
"class": "SP800-53",
"title": "Privacy Impact Assessments",
"props": [
{
"name": "label",
"value": "RA-08",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-8"
},
{
"name": "label",
"value": "RA-08",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-08"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#7b0b9634-741a-4335-b6fa-161228c3a76e",
"rel": "reference"
},
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#d229ae60-51dd-4d7b-a8bf-1f7195cc7561",
"rel": "reference"
},
{
"href": "#cm-4",
"rel": "related"
},
{
"href": "#cm-9",
"rel": "related"
},
{
"href": "#cm-13",
"rel": "related"
},
{
"href": "#pt-2",
"rel": "related"
},
{
"href": "#pt-3",
"rel": "related"
},
{
"href": "#pt-5",
"rel": "related"
},
{
"href": "#ra-1",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-7",
"rel": "related"
}
],
"parts": [
{
"id": "ra-8_smt",
"name": "statement",
"prose": "Conduct privacy impact assessments for systems, programs, or other activities before:",
"parts": [
{
"id": "ra-8_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Developing or procuring information technology that processes personally identifiable information; and"
},
{
"id": "ra-8_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Initiating a new collection of personally identifiable information that:",
"parts": [
{
"id": "ra-8_smt.b.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Will be processed using information technology; and"
},
{
"id": "ra-8_smt.b.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Includes personally identifiable information permitting the physical or virtual (online) contacting of a specific individual, if identical questions have been posed to, or identical reporting requirements imposed on, ten or more individuals, other than agencies, instrumentalities, or employees of the federal government."
}
]
}
]
},
{
"id": "ra-8_gdn",
"name": "guidance",
"prose": "A privacy impact assessment is an analysis of how personally identifiable information is handled to ensure that handling conforms to applicable privacy requirements, determine the privacy risks associated with an information system or activity, and evaluate ways to mitigate privacy risks. A privacy impact assessment is both an analysis and a formal document that details the process and the outcome of the analysis.\n\nOrganizations conduct and develop a privacy impact assessment with sufficient clarity and specificity to demonstrate that the organization fully considered privacy and incorporated appropriate privacy protections from the earliest stages of the organization\u2019s activity and throughout the information life cycle. In order to conduct a meaningful privacy impact assessment, the organization\u2019s senior agency official for privacy works closely with program managers, system owners, information technology experts, security officials, counsel, and other relevant organization personnel. Moreover, a privacy impact assessment is not a time-restricted activity that is limited to a particular milestone or stage of the information system or personally identifiable information life cycles. Rather, the privacy analysis continues throughout the system and personally identifiable information life cycles. Accordingly, a privacy impact assessment is a living document that organizations update whenever changes to the information technology, changes to the organization\u2019s practices, or other factors alter the privacy risks associated with the use of such information technology.\n\nTo conduct the privacy impact assessment, organizations can use security and privacy risk assessments. Organizations may also use other related processes that may have different names, including privacy threshold analyses. A privacy impact assessment can also serve as notice to the public regarding the organization\u2019s practices with respect to privacy. Although conducting and publishing privacy impact assessments may be required by law, organizations may develop such policies in the absence of applicable laws. For federal agencies, privacy impact assessments may be required by [EGOV](#7b0b9634-741a-4335-b6fa-161228c3a76e) ; agencies should consult with their senior agency official for privacy and legal counsel on this requirement and be aware of the statutory exceptions and OMB guidance relating to the provision."
},
{
"id": "ra-8_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-08",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-8_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-08a.",
"class": "sp800-53a"
}
],
"prose": "privacy impact assessments are conducted for systems, programs, or other activities before developing or procuring information technology that processes personally identifiable information;",
"links": [
{
"href": "#ra-8_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-8_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-08b.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-8_obj.b-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-08b.[01]",
"class": "sp800-53a"
}
],
"prose": "privacy impact assessments are conducted for systems, programs, or other activities before initiating a collection of personally identifiable information that will be processed using information technology;",
"links": [
{
"href": "#ra-8_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "ra-8_obj.b-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-08b.[02]",
"class": "sp800-53a"
}
],
"prose": "privacy impact assessments are conducted for systems, programs, or other activities before initiating a collection of personally identifiable information that includes personally identifiable information permitting the physical or virtual (online) contacting of a specific individual, if identical questions have been posed to, or identical reporting requirements imposed on, ten or more individuals, other than agencies, instrumentalities, or employees of the federal government.",
"links": [
{
"href": "#ra-8_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-8_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-8_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-8_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-08-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nsecurity and privacy risk assessment reports\n\nacquisitions documents\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-8_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-08-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with assessment and auditing responsibilities\n\nsystem/network administrators\n\nsystem developers\n\nprogram managers\n\nlegal counsel\n\norganizational personnel with security and privacy responsibilities"
}
]
},
{
"id": "ra-8_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-08-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for assessments and audits\n\nmechanisms/tools supporting and/or implementing assessments and auditing"
}
]
}
]
},
{
"id": "ra-9",
"class": "SP800-53",
"title": "Criticality Analysis",
"params": [
{
"id": "ra-09_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "ra-9_prm_1"
},
{
"name": "label",
"value": "RA-09_ODP[01]",
"class": "sp800-53a"
}
],
"label": "systems, system components, or system services",
"guidelines": [
{
"prose": "systems, system components, or system services to be analyzed for criticality are defined;"
}
]
},
{
"id": "ra-09_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "ra-9_prm_2"
},
{
"name": "label",
"value": "RA-09_ODP[02]",
"class": "sp800-53a"
}
],
"label": "decision points in the system development life cycle",
"guidelines": [
{
"prose": "decision points in the system development life cycle when a criticality analysis is to be performed are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-09",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-9"
},
{
"name": "label",
"value": "RA-09",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-09"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#d4296805-2dca-4c63-a95f-eeccaa826aec",
"rel": "reference"
},
{
"href": "#cp-2",
"rel": "related"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#pl-8",
"rel": "related"
},
{
"href": "#pl-11",
"rel": "related"
},
{
"href": "#pm-1",
"rel": "related"
},
{
"href": "#pm-11",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
},
{
"href": "#sa-15",
"rel": "related"
},
{
"href": "#sa-20",
"rel": "related"
},
{
"href": "#sr-5",
"rel": "related"
}
],
"parts": [
{
"id": "ra-9_smt",
"name": "statement",
"prose": "Identify critical system components and functions by performing a criticality analysis for {{ insert: param, ra-09_odp.01 }} at {{ insert: param, ra-09_odp.02 }}."
},
{
"id": "ra-9_gdn",
"name": "guidance",
"prose": "Not all system components, functions, or services necessarily require significant protections. For example, criticality analysis is a key tenet of supply chain risk management and informs the prioritization of protection activities. The identification of critical system components and functions considers applicable laws, executive orders, regulations, directives, policies, standards, system functionality requirements, system and component interfaces, and system and component dependencies. Systems engineers conduct a functional decomposition of a system to identify mission-critical functions and components. The functional decomposition includes the identification of organizational missions supported by the system, decomposition into the specific functions to perform those missions, and traceability to the hardware, software, and firmware components that implement those functions, including when the functions are shared by many components within and external to the system.\n\nThe operational environment of a system or a system component may impact the criticality, including the connections to and dependencies on cyber-physical systems, devices, system-of-systems, and outsourced IT services. System components that allow unmediated access to critical system components or functions are considered critical due to the inherent vulnerabilities that such components create. Component and function criticality are assessed in terms of the impact of a component or function failure on the organizational missions that are supported by the system that contains the components and functions.\n\nCriticality analysis is performed when an architecture or design is being developed, modified, or upgraded. If such analysis is performed early in the system development life cycle, organizations may be able to modify the system design to reduce the critical nature of these components and functions, such as by adding redundancy or alternate paths into the system design. Criticality analysis can also influence the protection measures required by development contractors. In addition to criticality analysis for systems, system components, and system services, criticality analysis of information is an important consideration. Such analysis is conducted as part of security categorization in [RA-2](#ra-2)."
},
{
"id": "ra-9_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-09",
"class": "sp800-53a"
}
],
"prose": "critical system components and functions are identified by performing a criticality analysis for {{ insert: param, ra-09_odp.01 }} at {{ insert: param, ra-09_odp.02 }}.",
"links": [
{
"href": "#ra-9_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-9_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-09-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nassessment reports\n\ncriticality analysis/finalized criticality for each component/subcomponent\n\naudit records/event logs\n\nanalysis reports\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-9_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-09-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with assessment and auditing responsibilities\n\norganizational personnel with criticality analysis responsibilities\n\nsystem/network administrators\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-9_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-09-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for assessments and audits\n\nmechanisms/tools supporting and/or implementing assessments and auditing"
}
]
}
]
},
{
"id": "ra-10",
"class": "SP800-53",
"title": "Threat Hunting",
"params": [
{
"id": "ra-10_odp",
"props": [
{
"name": "alt-identifier",
"value": "ra-10_prm_1"
},
{
"name": "label",
"value": "RA-10_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency at which to employ the threat hunting capability is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "RA-10",
"class": "zero-padded"
},
{
"name": "label",
"value": "RA-10"
},
{
"name": "label",
"value": "RA-10",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "ra-10"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "system"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#ca-2",
"rel": "related"
},
{
"href": "#ca-7",
"rel": "related"
},
{
"href": "#ca-8",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-5",
"rel": "related"
},
{
"href": "#ra-6",
"rel": "related"
},
{
"href": "#si-4",
"rel": "related"
}
],
"parts": [
{
"id": "ra-10_smt",
"name": "statement",
"parts": [
{
"id": "ra-10_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Establish and maintain a cyber threat hunting capability to:",
"parts": [
{
"id": "ra-10_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Search for indicators of compromise in organizational systems; and"
},
{
"id": "ra-10_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Detect, track, and disrupt threats that evade existing controls; and"
}
]
},
{
"id": "ra-10_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Employ the threat hunting capability {{ insert: param, ra-10_odp }}."
}
]
},
{
"id": "ra-10_gdn",
"name": "guidance",
"prose": "Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The objective is to track and disrupt cyber adversaries as early as possible in the attack sequence and to measurably improve the speed and accuracy of organizational responses. Indications of compromise include unusual network traffic, unusual file changes, and the presence of malicious code. Threat hunting teams leverage existing threat intelligence and may create new threat intelligence, which is shared with peer organizations, Information Sharing and Analysis Organizations (ISAO), Information Sharing and Analysis Centers (ISAC), and relevant government departments and agencies."
},
{
"id": "ra-10_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-10",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-10_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-10a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "ra-10_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-10a.01",
"class": "sp800-53a"
}
],
"prose": "a cyber threat capability is established and maintained to search for indicators of compromise in organizational systems;",
"links": [
{
"href": "#ra-10_smt.a.1",
"rel": "assessment-for"
}
]
},
{
"id": "ra-10_obj.a.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-10a.02",
"class": "sp800-53a"
}
],
"prose": "a cyber threat capability is established and maintained to detect, track, and disrupt threats that evade existing controls;",
"links": [
{
"href": "#ra-10_smt.a.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-10_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "ra-10_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "RA-10b.",
"class": "sp800-53a"
}
],
"prose": "the threat hunting capability is employed {{ insert: param, ra-10_odp }}.",
"links": [
{
"href": "#ra-10_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#ra-10_smt",
"rel": "assessment-for"
}
]
},
{
"id": "ra-10_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "RA-10-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Risk assessment policy\n\nassessment reports\n\naudit records/event logs\n\nthreat hunting capability\n\nsystem security plan\n\nother relevant documents or records"
}
]
},
{
"id": "ra-10_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "RA-10-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with threat hunting responsibilities\n\nsystem/network administrators\n\norganizational personnel with security responsibilities"
}
]
},
{
"id": "ra-10_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "RA-10-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for assessments and audits\n\nmechanisms/tools supporting and/or implementing threat hunting capabilities"
}
]
}
]
}
]
}
}