# RA-7 — Risk Response

- **Control ID:** RA-7
- **Family:** [RA](/md/families/RA.md)
- **Baselines:** low, moderate, high
- **Enhancement of:** No content available.

## Description

Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.

## Discussion

Organizations have many options for responding to risk including mitigating risk by implementing new controls or strengthening existing controls, accepting risk with appropriate justification or rationale, sharing or transferring risk, or avoiding risk. The risk tolerance of the organization influences risk response decisions and actions. Risk response addresses the need to determine an appropriate response to risk before generating a plan of action and milestones entry. For example, the response may be to accept risk or reject risk, or it may be possible to mitigate the risk immediately so that a plan of action and milestones entry is not needed. However, if the risk response is to mitigate the risk, and the mitigation cannot be completed immediately, a plan of action and milestones entry is generated.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [GV.OC-05](/md/csf/GV.OC-05.md) — Outcomes, capabilities, and services that the organization depends on are understood and communicated
- [GV.OV-01](/md/csf/GV.OV-01.md) — Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- [GV.OV-02](/md/csf/GV.OV-02.md) — The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
- [GV.OV-03](/md/csf/GV.OV-03.md) — Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
- [GV.RM-01](/md/csf/GV.RM-01.md) — Risk management objectives are established and agreed to by organizational stakeholders
- [GV.RM-03](/md/csf/GV.RM-03.md) — Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
- [GV.SC-03](/md/csf/GV.SC-03.md) — Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- [GV.SC-09](/md/csf/GV.SC-09.md) — Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- [GV.SC-10](/md/csf/GV.SC-10.md) — Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
- [ID.IM-01](/md/csf/ID.IM-01.md) — Improvements are identified from evaluations
- [ID.IM-02](/md/csf/ID.IM-02.md) — ID.IM-02
- [ID.IM-03](/md/csf/ID.IM-03.md) — Improvements are identified from execution of operational processes, procedures, and activities
- [ID.RA-05](/md/csf/ID.RA-05.md) — Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
- [ID.RA-06](/md/csf/ID.RA-06.md) — Risk responses are chosen, prioritized, planned, tracked, and communicated
- [RS.AN-08](/md/csf/RS.AN-08.md) — An incident's magnitude is estimated and validated

## Related controls

- [CA-5](/md/controls/CA-5.md)
- [IR-9](/md/controls/IR-9.md)
- [PM-4](/md/controls/PM-4.md)
- [PM-28](/md/controls/PM-28.md)
- [RA-2](/md/controls/RA-2.md)
- [RA-3](/md/controls/RA-3.md)
- [SR-2](/md/controls/SR-2.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
