PlumbTrackLive demoGRC Risk System

← control library

Criticality Analysis RA-9

Risk Assessment · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds RA-9 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Risk Assessment family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

RA-9 (Criticality Analysis) is about finding the parts of a system that really matter. You examine the components, functions, and services and identify which ones the mission depends on — the pieces whose failure or compromise would hurt the most. You do this at set points in the system’s life (for example, during design and after major changes). It is a Moderate-baseline control that helps you focus protection where it counts.

What good looks like

Framework mapping

How to move it toward Implemented