id: "RA-03(02)" title: "Use of All-source Intelligence" family: "RA" family_name: "Risk Assessment" sort_id: "ra-03.02" priority: "P1" implementation_level: "organization" parent: "RA-03" enhancement: True


Statement

Use all-source intelligence to assist in the analysis of risk.

Guidance

Organizations employ all-source intelligence to inform engineering, acquisition, and risk management decisions. All-source intelligence consists of information derived from all available sources, including publicly available or open-source information, measurement and signature intelligence, human intelligence, signals intelligence, and imagery intelligence. All-source intelligence is used to analyze the risk of vulnerabilities (both intentional and unintentional) from development, manufacturing, and delivery processes, people, and the environment. The risk analysis may be performed on suppliers at multiple tiers in the supply chain sufficient to manage risks. Organizations may develop agreements to share all-source intelligence information or resulting decisions with other organizations, as appropriate.

Assessment Objective

all-source intelligence is used to assist in the analysis of risk.

Risk assessment policy

security planning policy and procedures

procedures addressing organizational assessments of risk

risk assessment

risk assessment results

risk assessment reviews

risk assessment updates

risk intelligence reports

system security plan

other relevant documents or records

Organizational personnel with risk assessment responsibilities

organizational personnel with security responsibilities

Organizational processes for risk assessment

mechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment