id: "RA-03(03)" title: "Dynamic Threat Awareness" family: "RA" family_name: "Risk Assessment" sort_id: "ra-03.03" priority: "P1" implementation_level: "organization" parent: "RA-03" enhancement: True
Statement
Determine the current cyber threat environment on an ongoing basis using {{ insert: param, ra-03.03_odp }}.
Guidance
The threat awareness information that is gathered feeds into the organization’s information security operations to ensure that procedures are updated in response to the changing threat environment. For example, at higher threat levels, organizations may change the privilege or authentication thresholds required to perform certain operations.
Assessment Objective
the current cyber threat environment is determined on an ongoing basis using {{ insert: param, ra-03.03_odp }}.
Risk assessment policy
security planning policy and procedures
procedures addressing organizational assessments of risk
risk assessment
risk assessment results
risk assessment reviews
risk assessment updates
risk reports
system security plan
other relevant documents or records
Organizational personnel with risk assessment responsibilities
organizational personnel with security responsibilities
Organizational processes for risk assessment
mechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment