NIST CSF ID.RA - Risk Assessment
Identify, assess, prioritize, and record cybersecurity risks through vulnerability identification, threat intelligence, impact analysis, and structured risk response planning
Where this comes from
Provision: ID.RA - Risk Assessment
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section ID.RA (Risk Assessment), Sub-categories ID.RA-01 through ID.RA-10
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
- Service collects behavioral data
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assessment covers data flows, the risks to the affected group, and likelihood/severity
- Each identified risk has a mitigation mapped to a concrete control or backlog item
- The assessment is dated, has named sign-off, and is scheduled for review
- The assessment is retrievable for regulators on request
- Signed assessment document is stored and version-controlled
Evidence an auditor expects
- Assessment documentDocument review
Security risk assessment
Risk assessment covering children's data per NIST CSF
Questions people ask
- Does NIST CSF ID.RA - Risk Assessment apply to my service?
- It applies when Data categories collected — any answer; Service collects behavioral data.
- From when does this apply?
- NIST CSF ID.RA - Risk Assessment applies from 26 February 2024. Its current status is: in force.
- What evidence does an auditor expect?
- Security risk assessment.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.