{"data":{"id":"RA-04","name":"Risk Assessment Update","family":"RA","family_name":"Risk Assessment","withdrawn":true,"incorporated_into":["RA-03"],"description":"The organization updates the risk assessment [Assignment: organization-defined frequency] or whenever there are significant changes to the information system, the facilities where the system resides, or other conditions that may impact the security or accreditation status of the system.","supplemental_guidance":"The organization develops and documents specific criteria for what is considered significant change to the information system. NIST Special Publication 800-30 provides guidance on conducting risk assessment updates.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"RA-04","name":"Risk Assessment Update","description":"","discussion":"","related_controls":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.2.4","A.5.2"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.36","Hygiene.41","SecNumCloud.7.2"],"osfi_b13":["B-13.1.3","B-13.1.4"],"finma_circular":["IV.B.c(54)","IV.B.c(55)"],"gdpr":["Art.32(1)(d)","Art.35(11)"],"dora":["Art.6(4)","Art.6(5)"],"bio2":[],"rbi_csf":[],"fisc":[],"lgpd_bcb":["BCB.Art.18","BCB.Art.19"],"hkma_tme1":["TME1.2.3"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-4"],"cbuae":["CR-2"],"bog_cisd":["CISD-III"],"bom_ctrm":["1.4","2.1"],"cbe_csf":["CRM-1"],"cbn_csf":["Part2.1","Part2.2"],"sa_js2":["JS2-6.2"],"eba_ict":["3.3.5"],"iosco_cyber":["LE-2"],"cmmc_2":["RA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.5.3"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: recorded as withdrawn in SP 800-53 Rev 5, incorporated into RA-03, from NIST's Rev 5.2.0 catalogue. 2026-10-03: baselines LMH to ---, withdrawn in Rev 5 and in no baseline of NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-011","SP-013"]}}