Skip to main content

πŸ’Ό ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated

  • Contextual name: πŸ’Ό ID.RA-06: Risk responses are chosen, prioritized, planned, tracked, and communicated
  • ID: /frameworks/nist-csf-v2.0/id-ra/06
  • Located in: πŸ’Ό Risk Assessment (ID.RA)

Description​

  1. Apply the vulnerability management plan's criteria for deciding whether to accept, transfer, mitigate, or avoid risk
  2. Apply the vulnerability management plan's criteria for selecting compensating controls to mitigate risk
  3. Track the progress of risk response implementation (e.g., plan of action and milestones [POA&M], risk register, risk detail report)
  4. Use risk assessment findings to inform risk response decisions and actions
  5. Communicate planned risk responses to affected stakeholders in priority order

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/id-ra/06
    • /frameworks/nist-csf-v1.1/rs-mi/03
    • /frameworks/nist-sp-800-53-r5/pm/09
    • /frameworks/nist-sp-800-53-r5/pm/18
    • /frameworks/nist-sp-800-53-r5/pm/30
    • /frameworks/nist-sp-800-53-r5/ra/07

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.RA-6: Risk responses are identified and prioritized
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks77
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-9 Risk Management Strategy
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-18 Privacy Program Plan
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-30 Supply Chain Risk Management Strategy1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό RA-7 Risk Response

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (7)​

PolicyLogic CountFlags
πŸ“ Azure Subscription Microsoft Defender For (Managed Instance) Azure SQL Databases is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For App Services is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Containers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Key Vault is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Servers is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For SQL Servers On Machines is not set to On 🟒1🟒 x6
πŸ“ Azure Subscription Microsoft Defender For Storage is not set to On 🟒1🟒 x6