FedRAMP Moderate
RA - Risk Assessment

FedRAMP Moderate RA-7: Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so that identified risk is treated rather than only recorded.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 26 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management

C5 (Germany) · 2 controls

  • C5-OIS-07 Application of the Risk Management Policy
  • C5-SP-03 Exceptions from Existing Policies and Instructions

DORA · 2 controls

ISO/IEC 42001:2023 · 2 controls

  • 6.1.3 AI risk treatment
  • 8.3 AI risk treatment

APRA CPS 234 · 1 control

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

CMMC 2.0 · 1 control

GDPR · 1 control

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 1 control

  • 5.8.1 Nonconformity and corrective action

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

NIST SP 800-218 · 1 control

  • RA-7 RA-7 Risk Response
  • RA-7 RA-7 Risk Response

SOC 2 · 1 control

  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in RA - Risk Assessment

You are reading one control. How much of FedRAMP Moderate have you already done?

FedRAMP Moderate RA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.

Query this from an agent

The graph holds this control, the 26 it maps to, and the evidence behind each claim, over MCP and REST.