PlumbTrackLive demoGRC Risk System

← internal audit

Audit — RA-3 — Risk Assessment

Framework: NIST SP 800-53 Rev.5 RA-3 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the current risk assessment (RA) report or system security plan (SSP) and confirm a documented risk assessment exists for the system and its operating environment that evaluates both likelihood of occurrence and impact (magnitude of harm) for identified threats.
Examine Examine the risk assessment to verify it ingests the system's FIPS 199 / RA-2 security categorization and current threat and vulnerability inputs (including RA-5 scan results and external threat intelligence) rather than being assessed in isolation.
Examine Examine version history, review dates, or sign-off records to confirm the risk assessment is reviewed and updated at the organization-defined frequency (for example, annually) and is not stale.
Interview Interview the system owner or risk owner to confirm the process for updating the risk assessment when significant changes occur to the system, its environment, or the threat landscape.
Test Test the change-triggered update requirement by selecting a recent significant change (major upgrade, new interconnection, or incident) and confirming the risk assessment was re-performed or updated in response.
Examine Examine distribution records or the recipient list to verify risk assessment results are documented and disseminated to the organization-defined personnel or roles (for example, the authorizing official and system owner).
Interview Interview personnel who consume the risk assessment to confirm its results actually inform authorization, control selection, and prioritization decisions (traceability from assessed risk to accepted or treated risk).