Skip to main content

πŸ’Ό RA-9 Criticality Analysis

  • Contextual name: πŸ’Ό RA-9 Criticality Analysis
  • ID: /frameworks/nist-sp-800-53-r5/ra/09
  • Located in: πŸ’Ό RA Risk Assessment

Description​

Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle].

Similar​

  • Internal
    • ID: dec-c-18fe24da

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό RA-9 Criticality Analysis (M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.OC-04: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated4
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-04: Suppliers are known and prioritized by criticality7
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό GV.SC-07: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship26
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.AM-05: Assets are prioritized based on classification, criticality, resources, and impact on the mission
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-04: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded7

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags