Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.RA-06 NIST Cybersecurity Framework 2.0
ID - Identify
NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated Risk responses are chosen, prioritized, planned, tracked, and communicated. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 104 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
6.1 Actions to address risks and opportunities 6.1.1 Determining risks and opportunities 8.3 Business continuity strategies and solutions 8.3.1 General 8.3.2 Identification of strategies and solutions 8.3.3 Selection of strategies and solutions 8.4.4 Business continuity plans 9.3.2 Management review input 5.4 Planning 5.4.1 Actions to address risks and opportunities 5.5.4 Communication 5.6.1 Operational planning and control 5.6.3 Information security risk treatment 5.7.1 Monitoring, measurement, analysis and evaluation 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 5.29 Information security during disruption 8.32 Change management 8.8 Management of technical vulnerabilities SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC9.1 CC9.1 Mitigating risks of business disruption CPS220-04 Maintenance of a Risk Management Framework CPS220-16 Management Information System and Data Framework CPS220-P22 Framework Structure for Managing Each Material Risk CPS220-P35 Required Content of Risk Management Policies and Procedures CIS-18.3 Remediate Penetration Test Findings CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process CIS-7.7 Remediate Detected Vulnerabilities 6.1 Actions to address risks and opportunities 6.1.3 AI risk treatment 6.2 AI objectives and planning to achieve them 8.3 AI risk treatment ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions ANSSI-HYG-41 Conduct a Formal Risk Analysis CPS234-21 Implementation of Information Security Controls CPS234-28 Escalation of Unremediated Testing Deficiencies CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days ISM-1564 Plan of action and milestones ISM-1634 Selecting and tailoring controls ISM-1809 Compensating controls for unsupported systems CA-5 Plan of Action and Milestones RA-3 Risk Assessment RA-7 Risk Response 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.4.4 11.4.4 Correct exploitable findings from penetration tests 6.3.3 6.3.3 Timely installation of security patches CPS230-24 Design and Embedding of Internal Controls CPS230-P31 Remediation of Material Operational Risk Weaknesses ADMF-5.1 Implement risk-based protection controls ADMF-5.5 Manage and accept residual risk SEC04-BP04 Initiate remediation for non-compliant resources SEC06-BP01 Perform vulnerability management CA-5 Plan of Action and Milestones RA-3 Risk Assessment 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents ID.RA-6 ID.RA-6: Risk responses are identified and prioritized RS.MI-3 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks ID.RA-6 ID.RA-6: Risk responses are identified and prioritized RS.MI-3 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks 3.11.4e Security Solution Rationale Document 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring E8-PATCHAPP-ML3 Patch Applications (ML3) AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities C5-OIS-07 Application of the Risk Management Policy CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies Art.21.4 Take corrective measures without undue delay on finding that the measures are not met ID.RA-06 ID.RA-06 Criteria guide risk response decisions to prevent incidents and recurrence Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.