Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue RA-02: RA-02 Security categorization

The organisation categorizes the system and the information it processes, stores and transmits, documents the result with rationale in the system security plan, and has the authorizing official or delegate review and approve the categorization. The GC discussion asks for organisation-wide categorization involving the CIO, security, privacy, system, business and information owners, considering injury to other organisations and to national and non-national interests. 1 enhancement.

Maintained by Gerard Blokdyk

Other controls in RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.