← Controls / RA

RA-02 Security Categorization

Risk Assessment

Low Moderate High

Description

a. Categorize the system and information it processes, stores, and transmits; b. Document the security categorization results, including supporting rationale, in the security plan for the system; and c. Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.

Supplemental Guidance

Security categories describe the potential adverse impacts or negative consequences to organizational operations, organizational assets, and individuals if organizational information and systems are compromised through a loss of confidentiality, integrity, or availability. Security categorization is also a type of asset loss characterization in systems security engineering processes that is carried out throughout the system development life cycle. Organizations can use privacy risk assessments or privacy impact assessments to better understand the potential adverse effects on individuals. [CNSSI 1253] provides additional guidance on categorization for national security systems. Organizations conduct the security categorization process as an organization-wide activity with the direct involvement of chief information officers, senior agency information security officers, senior agency officials for privacy, system owners, mission and business owners, and information owners or stewards. Organizations consider the potential adverse impacts to other organizations and, in accordance with [USA PATRIOT] and Homeland Security Presidential Directives, potential national-level adverse impacts. Security categorization processes facilitate the development of inventories of information assets and, along with CM-8, mappings to specific system components where information is processed, stored, or transmitted. The security categorization process is revisited throughout the system development life cycle to ensure that the security categories remain accurate and relevant.

Changes from Rev 4

Control text modifies categorization requirement to include information processed, stored, and transmitted Discussion expanded to explain benefits

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

RA-02(01) Impact-level Prioritization

Conduct an impact-level prioritization of organizational systems to obtain additional granularity on system impact levels.

Compliance Mappings

ISO 27001:2022

6.1A.5.12A.5.13

ISO 27002:2022

5.125.13

COBIT 2019

APO12APO14

CIS Controls v8

CIS 3CIS 3.2CIS 3.7CIS 15.3

NIST CSF 2.0

GV.RM-06ID.AM-05ID.AM-07ID.RA-04ID.RA-05

SOC 2 TSC

CC3.2

PCI DSS v4.0.1

12.3

CSA CCM v4

DCS-05DSP-04

CSA AICM v1

DCS-05DSP-04

FINOS CCC

CCC-C16

ISO 42001:2023

A.5.2

IEC 62443

2-1 4.3

PRA Operational Resilience

PS6/21-2.1

APRA CPS 234

Para 21

ANSSI

Hygiene.8Hygiene.41SecNumCloud.9.1

FINMA Circular 2023/1

IV.B.c(54)IV.B.c(55)IV.D(78)

OSFI B-13

B-13.1.3B-13.3.1

EU GDPR

Art.30(1)Art.35(7)(a)

EU DORA

Art.8(1)Art.8(4)

BIO2

5.125.13

RBI CSF

Annex1.1ITGRCA.9

FISC Security Guidelines

FISC.O9

LGPD + BCB 4893

BCB.Art.5-Supp

HKMA TM-E-1

TME1.7.2

MLPS 2.0

8.1.9.1

DNB Good Practice

DNB.2.2DNB.4.1DNB.6.1

SAMA CSF

1.82.1

NCA ECC

1-52-12-7

UAE IA

T2T4

CBB TM

TM-4TM-9

Qatar NIA

AMRM

CBUAE

CR-2

CBE CSF

CRM-1CRM-2

SA JS2

JS2-6.1JS2-6.2

CBN CSF

Part2.1Part3.1

BoG CISD

CISD-III

POPIA

s17

BoM CTRM

1.42.1

IOSCO Cyber Resilience

ID-1ID-3ID-4

BCBS 239

Principle 4Principle 8

CPMI-IOSCO PFMI

CG.IDPFMI.P3

FFIEC IS

II.AII.BII.C.5

NYDFS 500

500.9

HIPAA Security Rule

§164.308(a)(1)(i)§164.308(a)(1)(ii)(A)§164.308(a)(7)(ii)(E)

ECB CROE

CROE.2.2.1CROE.2.2.2

EBA ICT Guidelines

3.3.23.3.3

SEBI CSCRF

CLASSIFYID.AMID.RA

BOT Cyber Resilience

Ch1.2

CMMC 2.0

RA

NERC CIP

CIP-002-7

10 CFR 73.54

73.54(a)RG5.71-C-PL

DOE C2M2 v2.1

RISKTHREAT

API 1164

Sec 4

AWIA

AWWA Sec 2Sec 2013(a)

IAEA NSS 17-T

Sec 4

CBEST

CBEST.3

ISAE 3402

Clause 1Clause 3

Solvency II

Art.44(2)DR.266-DataSecEIOPA-ICT-4.3

Lloyd's Minimum Standards

MS10.2

NAIC Insurance Data Security

34A

PRA SS1/23

P1.1P1.2

FCA SYSC 13

SYSC 13.5.2

HITRUST CSF v11

00.b03.a07.a07.b

FDA 21 CFR Part 11

§11.1§11.2

FDA Cybersecurity Guidance

SPDF-2

ISO 27799

5.38.18.2

NHS DSPT

NDG-5.3

MiCA

Art.35(1)

Basel SCO60

SCO60.1SCO60.2SCO60.4

BSSC Standards

GSP-02

SEC Custody (Digital Assets)

SEC-CD-09

ISO 17799 (legacy)

7.2.1

COBIT 4.1 (legacy)

PO9.2