RSK-02—Risk-Based Security Categorization
Weight: 9
>Control Description
Mechanisms exist to categorize Technology Assets, Applications, Services and/or Data (TAASD) in accordance with applicable laws, regulations and contractual obligations that:
(1) Document the security categorization results (including supporting rationale) in the security plan for systems; and
(2) Ensure the security categorization decision is reviewed and approved by the asset owner.
>Cross-Framework Mappings
NIST CSF 2.0
ISO 27001:2022
Canada ITSP 10.171
ISO 27001:2022 (Detailed)
ISO 27701
NIST SP 800-171 Rev 3
HIPAA Simplification 2013
SEC Cybersecurity Rule
NY DFS 23 NYCRR 500
Ask AI
Configure your API key to use AI features.