id: "RA-03(03)" title: "Dynamic Threat Awareness" family: "RA" family_name: "Risk Assessment" sort_id: "ra-03.03" priority: "P1" implementation_level: "organization" parent: "RA-03" enhancement: True


Statement

Determine the current cyber threat environment on an ongoing basis using {{ insert: param, ra-03.03_odp }}.

Guidance

The threat awareness information that is gathered feeds into the organization’s information security operations to ensure that procedures are updated in response to the changing threat environment. For example, at higher threat levels, organizations may change the privilege or authentication thresholds required to perform certain operations.

Assessment Objective

the current cyber threat environment is determined on an ongoing basis using {{ insert: param, ra-03.03_odp }}.

Risk assessment policy

security planning policy and procedures

procedures addressing organizational assessments of risk

risk assessment

risk assessment results

risk assessment reviews

risk assessment updates

risk reports

system security plan

other relevant documents or records

Organizational personnel with risk assessment responsibilities

organizational personnel with security responsibilities

Organizational processes for risk assessment

mechanisms supporting and/or conducting, documenting, reviewing, disseminating, and updating the risk assessment