Execute the Assess step per NIST SP 800-39 Chapter 3 Section 3.2 using NIST SP 800-30 (Risk Assessments) as the supporting methodology. Risk assessment must occur at all three tiers: Tier 1 organisation-wide assessment (strategic risk + supply chain + geopolitical + mission dependency), Tier 2 mission and business process assessment (architecture risk + information protection prioritisation + cross-system dependencies), Tier 3 information system assessment (categorisation + threat events + vulnerabilities + likelihood + impact + system risk). Assessments must use a methodology consistent with the risk frame established in Frame. Outputs feed the Respond step and inform risk-based decisions at each tier. The Assess step at Tier 3 directly feeds the NIST SP 800-37 RMF Prepare (P-3 + P-14) and Authorize (R-2) steps.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.