Policy and Procedures RA-1
Risk Assessment · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds RA-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Risk Assessment family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
RA-1 (Policy and Procedures) is the written foundation for the whole Risk Assessment (RA) family. It asks you to create, share, and keep current two things: a risk assessment policy (who is responsible, why you assess risk, and how it lines up with the laws and standards you must follow) and the procedures that turn that policy into repeatable steps. It is a Low-baseline control that every other RA control leans on.
What good looks like
- Write a risk assessment policy that covers purpose, scope, roles, responsibilities, and management commitment.
- Make sure the policy is consistent with the laws, regulations, and standards you have to follow.
- Write procedures that turn the policy into repeatable steps — how a risk assessment actually gets done here.
- Name an owner — one official responsible for developing and maintaining the policy and procedures.
- Share the policy with the people who need it, and review and update it on a set schedule and after major events (for example, a breach or a big system change).
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
How to move it toward Implemented
- Draft a one- to two-page risk assessment policy for the lab server: purpose, scope, who approves, and a review cadence (for example, yearly and after any major change).
- Save it as a dated document in a known place (for example,
/etc/plumbtrack/policies/ra-policy.mdor your document store) and record the named owner. - Add procedures that spell out how a risk assessment is run on this asset — the steps, the tools, and where results are filed.
- Attach that policy and procedures document as hardening evidence on the asset, naming
RA-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.