NIST SP 800-53 Rev 5
RA - Risk Assessment

NIST SP 800-53 Rev 5 RA-2: Security categorization

Requires the system and the information it processes, stores and transmits to be categorized, the categorization result and its rationale to be documented in the security plan, and the authorizing official or their representative to review and approve the categorization decision.

What else in your programme already covers this

This control maps to 237 controls across 132 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ADMF-3.3 Apply overarching categorisation considerations
  • ADMF-4.1 Establish a data categorisation matrix
  • ADMF-4.2 Assess confidentiality, integrity and availability impact
  • ADMF-4.4 Assign datasets to risk tiers
  • ADMF-5.4 Build a data protection control matrix
  • ADMF-6.3 Review categories assigned to datasets
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

API 1164 · 3 controls

  • SEC07-BP01 Understand your data classification scheme
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • SEC07-BP03 Automate identification and classification
  • ASBv3-DP-1 Discover, classify, and label sensitive data
  • ASBv3-GS-3 Define and implement data protection strategy
  • ASBv3-IR-5 Detection and analysis - prioritize incidents

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

IEC 62443 · 3 controls

ISO 27005 · 3 controls

ISO 27019 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 29134:2023 · 3 controls

NIST SP 1800-32 · 3 controls

DORA · 2 controls

FedRAMP High · 2 controls

  • RA-1 Policy and Procedures
  • RA-2 Security Categorization

FedRAMP Moderate · 2 controls

  • RA-1 Policy and Procedures
  • RA-2 Security Categorization

ISO 22301:2019 · 2 controls

  • 8.2.2 Business impact analysis
  • 8.2.3 Risk assessment

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27003:2017 · 2 controls

ISO/IEC 27014:2020 · 2 controls

NIST SP 800-190 · 2 controls

  • RA-1 Policy and Procedures
  • RA-2 Security Categorization
  • RA-1 Policy and Procedures
  • RA-2 Security Categorization
  • RA-1 Policy and Procedures
  • RA-2 Security Categorization
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • CPS230-11 Identification, Assessment and Management of Operational Risk

APRA CPS 234 · 1 control

  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • 4.3.1 Risk Assessment and Impact Analysis
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

C5 (Germany) · 1 control

  • C5-AM-06 Asset Classification and Labelling

CIS Controls v8 · 1 control

  • CIS-3.7 Establish and Maintain a Data Classification Scheme

EU AI Act · 1 control

  • EUAI-Art.6 Classification rules for high-risk AI systems
  • QMSR-820.45 Device labelling and packaging controls (§820.45)

GDPR · 1 control

ISO 13485 · 1 control

  • ISO13485-06 Security management process and risk analysis

ISO 22000 · 1 control

ISO 27001:2022 · 1 control

  • 5.12 Classification of information

ISO 27002:2022 · 1 control

  • 5.12 Classification of information

ISO 27043 · 1 control

ISO 27799 · 1 control

  • ISO27799-06 Security management process and risk analysis

ISO 45001 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ISO/IEC 42001:2023 · 1 control

  • 4.3 Determining the scope of the management system

ISO/SAE 21434 · 1 control

  • 3.11 Encrypt Sensitive Data at Rest
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • QRCM-1.3 Data Classification for Migration
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment

PCI DSS 4.0 · 1 control

  • 9.4.2 Media classified by sensitivity

PDPA Singapore · 1 control

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 1 control

  • PDPATH-4 DPIA, Privacy by Design, Children's Data

POPIA · 1 control

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation

PTES · 1 control

  • NORWAY-4 DPIA, Privacy by Design, Records of Processing

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training

SASB Standards · 1 control

  • SECCLIM-2 Risk Management: Identification, Assessment, Integration

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance

SOC 2 · 1 control

  • SOC2-C1.1 Confidential information is identified and protected during receipt, processing, storage

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator

Taiwan PDPA · 1 control

  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-3 Self-Assessment and Board Engagement
  • s.54(5) Statement Content Requirements
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in RA - Risk Assessment

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 RA-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 300 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 237 it maps to, and the evidence behind each claim, over MCP and REST.