# RA-04 Risk Assessment Update

NIST SP 800-53 control. Family: RA Risk Assessment. Function: detective. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into RA-03.

Statement: The organization updates the risk assessment [Assignment: organization-defined frequency] or whenever there are significant changes to the information system, the facilities where the system resides, or other conditions that may impact the security or accreditation status of the system.
Guidance: The organization develops and documents specific criteria for what is considered significant change to the information system. NIST Special Publication 800-30 provides guidance on conducting risk assessment updates.

## Patterns that use it (4)
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-013 Data Security Pattern

## Clauses by framework (19 frameworks)
- iso_42001_2023: A.2.4, A.5.2
- anssi: Hygiene.36, Hygiene.41, SecNumCloud.7.2
- osfi_b13: B-13.1.3, B-13.1.4
- finma_circular: IV.B.c(54), IV.B.c(55)
- gdpr: Art.32(1)(d), Art.35(11)
- dora: Art.6(4), Art.6(5)
- lgpd_bcb: BCB.Art.18, BCB.Art.19
- hkma_tme1: TME1.2.3
- cbb_tm: TM-4
- cbuae: CR-2
- bog_cisd: CISD-III
- bom_ctrm: 1.4, 2.1
- cbe_csf: CRM-1
- cbn_csf: Part2.1, Part2.2
- sa_js2: JS2-6.2
- eba_ict: 3.3.5
- iosco_cyber: LE-2
- cmmc_2: RA
- fca_sysc_13: SYSC 13.5.3

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/RA-04
- Clauses only: /api/v1/controls/RA-04?fields=mappings
- Page for people: /controls/ra-04/
