Under active development Content is continuously updated and improved

RSK-02Risk-Based Security Categorization

Weight: 9

>Control Description

Mechanisms exist to categorize Technology Assets, Applications, Services and/or Data (TAASD) in accordance with applicable laws, regulations and contractual obligations that: (1) Document the security categorization results (including supporting rationale) in the security plan for systems; and (2) Ensure the security categorization decision is reviewed and approved by the asset owner.

>Cross-Framework Mappings

NIST SP 800-53 r5

NIST CSF 2.0

ISO 27001:2022

PCI DSS v4.0.1

CIS Controls v8

SOC 2 TSC

FedRAMP Rev 5

Canada ITSP 10.171

SOC 2 TSC (Detailed)

CIS Controls v8.1 (Detailed)

ISO 27001:2022 (Detailed)

NIST SP 800-161

NIST SP 800-171 Rev 3

HIPAA Simplification 2013

NY DFS 23 NYCRR 500

Ask AI

Configure your API key to use AI features.