Risk Assessment (RA)¶
Domain: Risk Assessment (RA)
Requirements in this domain: 3
Assessment Objectives in this domain: 9
RA.L2-3.11.1¶
RA.L2-3.11.1[a]¶
Assessment Objective
the frequency to assess risk to organizational operations, organizational assets, and individuals is defined.
Collection Approach: Document
Potential Evidence Examples
Risk Assessment Policy stating how often formal risk assessments must be performed (e.g., annually).
RA.L2-3.11.1[b]¶
Assessment Objective
risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.
Collection Approach: Artifact
Potential Evidence Examples
Most recent risk assessment report, dated within the defined frequency, addressing risk to organizational operations, assets, and individuals from the CUI-processing system.
Assessment Guide – Further Discussion
- Have initial and periodic risk assessments been conducted [b]?
- Are methods defined for assessing risk (e.g., reviewing security assessments, incident reports, and security advisories, identifying threat sources, threat events, and vulnerabilities, and determining likelihood, impact, and overall risk to the confidentiality of CUI) [b]?
RA.L2-3.11.2¶
RA.L2-3.11.2[a]¶
Assessment Objective
the frequency to scan for vulnerabilities in an organizational system and its applications that process, store, or transmit CUI is defined.
Collection Approach: Document
Potential Evidence Examples
Vulnerability Management Policy/SOP defining the required scanning frequency for organizational systems and applications that process, store, or transmit CUI.
Assessment Guide – Further Discussion
- Are vulnerability scans performed on a defined frequency or randomly in accordance with company policy [a,b,c]?
- Is the frequency specified for vulnerability scans to be performed in organizational systems and applications (e.g., continuous passive scanning, scheduled active scans) [a]?
RA.L2-3.11.2[b]¶
Assessment Objective
vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI with the defined frequency.
Collection Approach: Screen Share
Potential Evidence Examples
Screen share of the vulnerability scanner's schedule configuration plus the most recent scan results for systems, confirming scans occur at least as often as the defined frequency.
Assessment Guide – Further Discussion
Are vulnerability scans performed on a defined frequency or randomly in accordance with company policy [a,b,c]?
RA.L2-3.11.2[c]¶
Assessment Objective
vulnerability scans are performed in an application that contains CUI with the defined frequency.
Collection Approach: Screen Share
Potential Evidence Examples
Screen share of the vulnerability scanner's schedule configuration plus the most recent scan results for applications containing CUI, confirming scans occur at least as often as the defined frequency.
Assessment Guide – Further Discussion
Are vulnerability scans performed on a defined frequency or randomly in accordance with company policy [a,b,c]?
RA.L2-3.11.2[d]¶
Assessment Objective
vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI when new vulnerabilities are identified.
Collection Approach: Screen Share
Potential Evidence Examples
Evidence of an ad hoc/out-of-cycle scan triggered by a newly announced vulnerability (e.g., scanner signature update log and a corresponding on-demand scan result) for organizational systems.
Assessment Guide – Further Discussion
- Are systems periodically scanned for common and new vulnerabilities [d,e]?
- Is the list of scanned system vulnerabilities updated on a defined frequency or when new vulnerabilities are identified and reported [d,e]?
RA.L2-3.11.2[e]¶
Assessment Objective
vulnerability scans are performed in an application that contains CUI when new vulnerabilities are identified.
Collection Approach: Screen Share
Potential Evidence Examples
Evidence of an ad hoc/out-of-cycle scan triggered by a newly announced vulnerability for applications containing CUI (e.g., updated scan-engine signatures and resulting scan report).
RA.L2-3.11.3¶
RA.L2-3.11.3[a]¶
Assessment Objective
vulnerabilities are identified.
Collection Approach: Artifact
Potential Evidence Examples
Vulnerability scan report(s) showing identified vulnerabilities with severity ratings for in-scope systems/applications.
RA.L2-3.11.3[b]¶
Assessment Objective
vulnerabilities are remediated in accordance with risk assessments.
Collection Approach: Artifact
Potential Evidence Examples
Remediation evidence (e.g., rescan showing a vulnerability resolved, patch-deployment ticket, or POA&M entry) showing vulnerabilities are remediated on a timeline consistent with the organization's risk assessment/risk-based prioritization.
Assessment Guide – Further Discussion
- Are the results of risk assessments used to prioritize vulnerabilities for remediation [b]?
- For any given vulnerability is action taken for remediation, acceptance, avoidance, or transference of the vulnerability risk [b]?
- Are all high risk vulnerabilities prioritized [b]?