{"data":{"id":"RA-07","name":"Risk Response","family":"RA","family_name":"Risk Assessment","withdrawn":false,"description":"Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.","supplemental_guidance":"Organizations have many options for responding to risk including mitigating risk by implementing new controls or strengthening existing controls, accepting risk with appropriate justification or rationale, sharing or transferring risk, or avoiding risk. The risk tolerance of the organization influences risk response decisions and actions. Risk response addresses the need to determine an appropriate response to risk before generating a plan of action and milestones entry. For example, the response may be to accept risk or reject risk, or it may be possible to mitigate the risk immediately so that a plan of action and milestones entry is not needed. However, if the risk response is to mitigate the risk, and the mitigation cannot be completed immediately, a plan of action and milestones entry is generated.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"RA-07","name":"Risk Response","description":"Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.","discussion":"Organizations have many options for responding to risk including mitigating risk by implementing new controls or strengthening existing controls, accepting risk with appropriate justification or rationale, sharing or transferring risk, or avoiding risk. The risk tolerance of the organization influences risk response decisions and actions. Risk response addresses the need to determine an appropriate response to risk before generating a plan of action and milestones entry. For example, the response may be to accept risk or reject risk, or it may be possible to mitigate the risk immediately so that a plan of action and milestones entry is not needed. However, if the risk response is to mitigate the risk, and the mitigation cannot be completed immediately, a plan of action and milestones entry is generated.","related_controls":["CA-05","IR-09","PM-04","PM-28","RA-02","RA-03","SR-02"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":true,"changes_from_rev4":"New control in Rev 5."}},"compliance_mappings":{"iso_27001_2022":["6.1","6.1.3","8.3","10.2"],"iso_27002_2022":["5.7"],"cobit_2019":["APO12","EDM03"],"pci_dss_v4":["12.3"],"nist_csf_2":["GV.OC-05","GV.OV-01","GV.OV-02","GV.OV-03","GV.RM-01","GV.RM-03","GV.RM-04","GV.SC-03","GV.SC-07","GV.SC-09","GV.SC-10","ID.IM-01","ID.IM-02","ID.IM-03","ID.RA-05","ID.RA-06","ID.RA-07","RS.AN-08"],"cis_controls_v8":[],"soc2_tsc":["CC3.2","CC9.1"],"finos_ccc":["CCC-C10"],"iso_42001_2023":["A.5.2","A.5.3"],"iec_62443":["2-1 4.3","2-1 4.4"],"asd_e8":[],"nis2":["Art. 21(2)(a)"],"apra_cps_234":["Para 15","Para 19-20","Para 26"],"mas_trm":["4"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.31","Hygiene.36","Hygiene.41","RGS.3.1","SecNumCloud.7.2","SecNumCloud.13.6"],"osfi_b13":["B-13.1.3","B-13.1.4","B-13.2.4","B-13.3.1"],"finma_circular":["IV.A(38)","IV.A(40)","IV.A(42)","IV.B.b(52)","IV.B.c(53)","IV.B.c(54)","IV.B.c(55)","IV.B.c(56)","IV.B.d(58)","V(101)","V(107)"],"gdpr":["Art.32(1)","Art.32(2)"],"dora":["Art.6(1)","Art.6(2)","Art.6(5)"],"bio2":["5.7"],"rbi_csf":["ITGRCA.22","ITGRCA.25"],"fisc":["FISC.O1","FISC.O12"],"lgpd_bcb":["BCB.Art.3-Supp"],"hkma_tme1":["TME1.2.3"],"mlps_2":[],"dnb_good_practice":["DNB.4.2","DNB.4.3","DNB.10.2","DNB.19.2"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-4","TM-11"],"cbuae":["CR-2"],"nca_ecc":["1-5","2-10"],"qatar_nia":["OS","RM"],"sama_csf":["1.8","3.5"],"uae_ia":["T2"],"bog_cisd":["CISD-III"],"bom_ctrm":["1.4","2.1","5.3"],"cbe_csf":["CRM-1"],"cbn_csf":["Part2.1","Part2.2"],"popia":["s19"],"sa_js2":["JS2-6.2"],"bcbs_239":["Principle 6","Principle 13"],"bot_cyber":["Ch1.2"],"cpmi_pfmi":["CG.LE","PFMI.P3"],"eba_ict":["3.3.3","3.3.4","3.3.5"],"ecb_croe":["CROE.2.2.1","CROE.2.8.1","CROE.2.8.2"],"ffiec_is":["II.A","II.A.2","II.B","II.D"],"hipaa_sr":["§164.308(a)(1)(ii)(A)","§164.308(a)(1)(ii)(B)"],"iosco_cyber":["GOV-3","ID-3","PFMI-3"],"nydfs_500":["500.5","500.9"],"sebi_cscrf":["DE.VA","GV.RM","ID.RA","VAPT"],"cmmc_2":["RA"],"nerc_cip":[],"nrc_73_54":["73.54(d)","RG5.71-C-PL"],"tsa_psd":["SD-1 Sec 4"],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["RISK","THREAT"],"api_1164":["Sec 4"],"awia":["Sec 2013(a)"],"iaea_nss":["Sec 4"],"pci_pts":[],"fips_140":["FIPS 140-3 §7.12"],"cbest":["CBEST.6"],"tiber_eu":["TIBER.CONF","TIBER.REM"],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.5.2","SYSC 13.5.3","SYSC 13.8.4","SYSC 13.8.5","SYSC 13.G.2"],"fda_21_cfr_11":["§11.2"],"fda_cyber":["CRA-3","INC-2","MON-2","SPDF-2","TM-3","TR-2","VR-1","VR-2"],"hitrust_csf":["00.b","03.a","03.b"],"iso_27799":[],"lloyds_ms":["MS8.11","MS10.1","MS10.2"],"naic_ds":["4-monitoring","4A","4E"],"nhs_dspt":[],"pra_ss1_23":["P4.5","P5.1"],"solvency_ii":["Art.44(1)","Art.44(2)","Art.45","DR.260","EIOPA-ICT-4.2"],"owasp_masvs_v2":[],"csa_ccm_v4":["AA-03","AA-06","CEK-07"],"csa_aicm":["A&A-03","A&A-06","CEK-07"],"ccss_v9":[],"mica":["Art.34(5)","Art.35(1)","Art.62(1)"],"basel_sco60":["SCO60.4","SCO60.5","SCO60.50","SCO60.85"],"bssc":["GSP-02"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 GV.OC-05, GV.OV-01, GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-03, GV.SC-03, GV.SC-09, GV.SC-10, ID.IM-01, ID.IM-02, ID.IM-03, RS.AN-08 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-018","SP-035","SP-045","SP-046"]}}