NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated

Risk responses are chosen, prioritized, planned, tracked, and communicated. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 104 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

ISO 22301:2019 · 8 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.1 Determining risks and opportunities
  • 8.3 Business continuity strategies and solutions
  • 8.3.1 General
  • 8.3.2 Identification of strategies and solutions
  • 8.3.3 Selection of strategies and solutions
  • 8.4.4 Business continuity plans
  • 9.3.2 Management review input

ISO 27701:2019 · 6 controls

  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.5.4 Communication
  • 5.6.1 Operational planning and control
  • 5.6.3 Information security risk treatment
  • 5.7.1 Monitoring, measurement, analysis and evaluation

ISO 27001:2022 · 5 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.26 Response to information security incidents
  • 5.29 Information security during disruption
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities

SOC 2 · 5 controls

  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-16 Management Information System and Data Framework
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

CIS Controls v8 · 4 controls

  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.7 Remediate Detected Vulnerabilities

ISO/IEC 42001:2023 · 4 controls

  • 6.1 Actions to address risks and opportunities
  • 6.1.3 AI risk treatment
  • 6.2 AI objectives and planning to achieve them
  • 8.3 AI risk treatment
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • ANSSI-HYG-41 Conduct a Formal Risk Analysis

APRA CPS 234 · 3 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • ISM-1564 Plan of action and milestones
  • ISM-1634 Selecting and tailoring controls
  • ISM-1809 Compensating controls for unsupported systems

FedRAMP High · 3 controls

  • CA-5 Plan of Action and Milestones
  • RA-3 Risk Assessment
  • RA-7 Risk Response

NIST SP 800-161 Rev 1 · 3 controls

PCI DSS 4.0 · 3 controls

  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 6.3.3 6.3.3 Timely installation of security patches
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • ADMF-5.1 Implement risk-based protection controls
  • ADMF-5.5 Manage and accept residual risk
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management

CMMC 2.0 · 2 controls

FedRAMP Moderate · 2 controls

  • CA-5 Plan of Action and Milestones
  • RA-3 Risk Assessment

HIPAA Security Rule · 2 controls

ISO 27002:2022 · 2 controls

  • 5.24 Information security incident management planning and preparation
  • 5.26 Response to information security incidents
  • ID.RA-6 ID.RA-6: Risk responses are identified and prioritized
  • RS.MI-3 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks
  • ID.RA-6 ID.RA-6: Risk responses are identified and prioritized
  • RS.MI-3 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.4e Security Solution Rationale Document
  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring

NIST SP 800-218 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

C5 (Germany) · 1 control

  • C5-OIS-07 Application of the Risk Management Policy
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

NIS2 Directive · 1 control

  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met
  • ID.RA-06 ID.RA-06 Criteria guide risk response decisions to prevent incidents and recurrence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.RA-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.