Risk Assessment RA-3
Risk Assessment · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds RA-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Risk Assessment family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
RA-3 (Risk Assessment) requires you to identify the threats and vulnerabilities facing a system, judge how likely each is and how much harm it would cause, then record that as a documented risk determination. It turns raw scan findings into a decision about the risk the system actually carries. It applies from the Low baseline up.
What good looks like
- Identify the threats to the system and the vulnerabilities each could exploit.
- Determine the likelihood of each threat and the magnitude of harm (impact) if it succeeds.
- Combine those into an overall risk determination and write it up in a risk assessment report.
- Review and update the assessment on a schedule and after significant changes to the system or its environment.
- Share the results with the roles who make risk-acceptance and remediation decisions.
Framework mapping
- NIST CSF 2.0 — ID.RA-04 — Potential impacts and likelihoods of threats exploiting vulnerabilities are identified
- CIS Controls v8 — Control 3 — Data protection decisions are driven by an understanding of risk to the asset
How to move it toward Implemented
- Author a system risk assessment for PROD-WEB-01: list the real threats (SSH (Secure Shell) brute-force, web exploit against the DVWA (Damn Vulnerable Web Application) target, configuration drift), rate each for likelihood and impact, and state an overall risk level.
- Feed in the inputs you already have — the Lynis findings (hardening index 68, five remediated) and the as-built snapshot — as evidence supporting the likelihood and impact ratings, rather than treating those scans as the risk assessment itself.
- Record the determination in a short, dated report that is reviewed and signed, and set a re-assessment cadence (for example, annually and after major changes).
- Attach that report as evidence naming RA-3 in the Requirement field to move it from 'Planned' toward 'Completed'.