|
controlRA-9
Criticality Analysis (RA-9)
Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
Security Baselines
MODERATEHIGHLOW
risk-assessmentvulnerabilitythreat
Why These Connect
Maps To11
These are equivalent or closely aligned requirements in other frameworks.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports26
These related controls work together — a change to one may affect the others.
Related Controls(16)
PL-2System Security and Privacy Plans (PL-2)
LMH
PL-8Security and Privacy Architectures (PL-8)MH
PL-11Baseline Tailoring (PL-11)LMH
PM-1Information Security Program Plan (PM-1)PM-9Risk Management Strategy (PM-9)PM-11Mission and Business Process Definition (PM-11)PM-32Purposing (PM-32)CP-2Contingency Plan (CP-2)LMH
RA-2Security Categorization (RA-2)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SA-15Development Process, Standards, and Tools (SA-15)MH
SA-20Customized Development of Critical Components (SA-20)SR-5Acquisition Strategies, Tools, and Methods (SR-5)LMH
SA-23Specialization (SA-23)SA-24Design For Cyber Resiliency (SA-24)SR-4Provenance (SR-4)Cross-Framework Mappings(11)
GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-05ID.AM-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-04ID.RA-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-04GV.OC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-05ID.AM-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-04ID.RA-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-04GV.OC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined systems, system components, or system services
Assignmentorganization-defined decision points in the system development life cycle