Quick-reference card
| Field | Value |
|---|---|
| Control ID | RA-07 |
| Control Name | Risk Response |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Risk Assessment |
| Baselines | LOW MODERATE HIGH PRIVACY |
| Relevance | Organization (First Party) |
| Risk Severity | Medium |
What this control requires
RA-07 requires your organization to act on every finding from security assessments, privacy assessments, monitoring, and audits based on your documented risk tolerance. The control doesn’t let findings sit in a spreadsheet. It demands a deliberate decision for each one, whether that decision is to mitigate, accept, transfer, or avoid the risk entirely.
In practice, this means every finding that surfaces through a cybersecurity risk assessment triggers a formal response workflow. Your team evaluates the finding against the organization’s risk tolerance thresholds, selects a response strategy, and either resolves the issue immediately or generates a plan of action and milestones (POA&M) entry to track remediation over time. The response must be documented, traceable, and consistent with how your organization defines acceptable risk.
The “so what” behind RA-07 is accountability. Without a structured risk response process, findings from assessments and audits pile up without clear ownership or resolution paths. Auditors don’t just want to see that you identified risks. They want evidence that you responded to them in a way that aligns with your stated risk tolerance and that each decision has a documented rationale.
Why it matters
Most organizations invest significant effort in identifying risks through assessments and monitoring, but the response side of the equation often breaks down. Findings get logged, acknowledged, and then deprioritized until the next audit cycle forces a reckoning. RA-07 exists because risk identification without disciplined response creates a false sense of security.
The compliance consequences of neglecting risk response are concrete. When auditors review your security program, they’ll compare your risk assessment findings against documented response actions. Gaps between what you found and what you did about it indicate a governance failure, one that can result in audit findings, conditional authorizations, or loss of an authorization to operate (ATO) entirely.
Beyond audit risk, an undisciplined risk assessment methodology and response process means your organization can’t prioritize effectively. Resources get allocated to whichever risks are loudest rather than which ones pose the greatest actual threat. Over time, the backlog of unaddressed findings grows, making each subsequent assessment cycle harder to manage and defend.
Organizations that treat risk response as a box-checking exercise also struggle with cross-functional alignment. Security findings often require action from teams outside the security organization, including IT operations, procurement, legal, and executive leadership. Without a formalized response framework, these handoffs fail quietly.
What auditors look for when risk response is weak
- Findings from security or privacy assessments that remain open with no documented response decision
- Risk acceptance decisions that lack a rationale or aren’t approved at the appropriate authority level
- Monitoring alerts that generate findings but have no documented triage or escalation process
- Audit results that repeat the same findings cycle after cycle, indicating unresolved prior responses
- Absence of POA&M entries for findings that require extended remediation timelines
How to implement
The most common failure in RA-07 implementation isn’t a lack of process documentation. It’s a mismatch between how the organization defines risk tolerance on paper and how teams actually respond to findings in practice. Closing that gap requires both clear governance structures and operational workflows that connect findings to decisions.
Establish a risk response framework
Start by defining your organization’s risk tolerance thresholds in measurable terms. Vague statements like “we accept moderate risk” don’t give practitioners enough guidance. Instead, specify criteria for each response strategy. For example, define the conditions under which a finding qualifies for acceptance versus requiring immediate mitigation. Document who has the authority to approve each type of response decision, typically tiered by risk severity.
Build a findings-to-response workflow
Every finding from a security assessment, privacy assessment, monitoring event, or audit should enter a centralized tracking system. For each finding, the workflow should capture the source of the finding, its severity rating, the selected response strategy (mitigate, accept, transfer, or avoid), the rationale for that selection, the responsible party, and the target resolution date. If the response is mitigation and the fix can’t happen immediately, generate a POA&M entry with milestones and a realistic timeline.
Connect response decisions to evidence
Your risk response documentation should create a clear audit trail. For each finding, auditors will look for the original assessment or monitoring report that surfaced the issue, a documented risk response decision with approval, and evidence that the response was carried out. Use your organization’s governance, risk, and compliance (GRC) platform or a dedicated risk register to maintain this chain of evidence. A cybersecurity risk assessment guide can help structure the upstream assessment process that feeds into RA-07 response workflows.
Review and validate response effectiveness
Risk response isn’t a one-time activity. Implement a periodic review cycle, typically quarterly, to evaluate whether previous response decisions remain appropriate. Risk tolerance can shift as the threat landscape changes or as the organization takes on new systems or business functions. Validate that accepted risks still fall within tolerance and that mitigated risks were actually resolved.
Common mistakes
- Treating risk acceptance as the default response rather than a deliberate, justified decision
- Failing to assign clear ownership for response actions, leaving findings in limbo
- Documenting risk tolerance at a high level without translating it into operational criteria teams can apply
- Generating POA&M entries without realistic milestones, turning them into a parking lot for stale findings
- Siloing risk response within the security team when findings require cross-functional action
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Risk response policy | Risk Assessment and Response Policy defining risk tolerance thresholds, response strategy criteria (mitigate, accept, transfer, avoid), and approval authority levels |
| Assessment reports | Security assessment and privacy assessment reports with documented findings, severity ratings, and response decisions for each finding |
| Risk register or POA&M | Plan of action and milestones entries tracking open findings with assigned owners, selected response strategies, milestones, and target completion dates |
| Audit response records | Audit findings log showing each audit result, the response decision, rationale, and evidence of follow-through or escalation |
| System security plan | System security plan (SSP) sections documenting risk tolerance definitions and the organizational risk response process |
| Privacy plan | Privacy plan documenting how privacy assessment findings are evaluated against risk tolerance and routed through the response workflow |
| Risk acceptance documentation | Signed risk acceptance memos with justification, residual risk analysis, and approval from the designated authorizing official |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 8.3 Information access restriction | Partial |
| NIST SP 800-171 Rev 3 | 03.11.04 Risk Response | Partial |
Related controls
- CA-05 — Plan of Action and Milestones: Manages the POA&M entries that RA-07 generates when risk response requires extended remediation timelines.
- IR-09 — Information Spillage Response: Addresses a specific type of incident response that may surface findings requiring an RA-07 risk response decision.
- PM-04 — Plan of Action and Milestones Process: Defines the organizational process for creating and maintaining POA&M entries referenced by RA-07 response actions.
- PM-28 — Risk Framing: Establishes the risk context and tolerance definitions that RA-07 uses to evaluate and justify response decisions.
- RA-02 — Security Categorization: Determines the impact level of systems, which directly influences the risk tolerance thresholds applied during RA-07 response.
- RA-03 — Risk Assessment: Produces the security and privacy assessment findings that RA-07 requires the organization to respond to.
- SR-02 — Supply Chain Risk Management Plan: Identifies supply chain risks that may require formal risk response decisions under RA-07.
Frequently asked questions
What is NIST SP 800-53 RA-07
RA-07 requires organizations to respond to findings from security assessments, privacy assessments, monitoring, and audits in accordance with their documented risk tolerance. The control ensures that identified risks don’t remain unaddressed by mandating a deliberate decision for each finding. Response options include mitigating the risk through new or strengthened controls, accepting the risk with documented justification, transferring or sharing the risk, or avoiding the risk entirely. Each response must be documented and traceable through evidence such as risk acceptance memos, POA&M entries, and assessment reports.
What happens if RA-07 is not implemented
Without RA-07, findings from security and privacy assessments accumulate without documented response decisions, creating a governance gap that auditors will flag during authorization reviews. The organization can’t demonstrate that it acts on its own risk findings, which undermines the credibility of the entire risk management program. Repeated assessment cycles will surface the same unresolved findings, and the absence of risk response records, such as signed risk acceptance documentation or POA&M entries with milestones, signals to auditors that the organization lacks the discipline to manage risk beyond identification.
How do you audit RA-07
Auditors verify RA-07 by tracing a sample of findings from security assessment reports, privacy assessment reports, monitoring outputs, and audit records back to documented response decisions. They check that each finding has a response strategy aligned with the organization’s stated risk tolerance, an approval at the appropriate authority level, and evidence of follow-through. Key artifacts include the risk assessment policy defining tolerance thresholds, POA&M entries for findings requiring extended remediation, and risk acceptance memos with signed justification for findings the organization chose not to mitigate.
What are the four risk response strategies in NIST
The four risk response strategies recognized across NIST frameworks are mitigation, acceptance, transfer (or sharing), and avoidance. Mitigation involves implementing new controls or strengthening existing ones to reduce the risk to an acceptable level, and it typically generates a POA&M entry when the fix can’t be completed immediately. Acceptance means the organization acknowledges the residual risk and documents a rationale, which must align with the risk tolerance thresholds defined in the organization’s risk assessment policy. Transfer shifts the risk to another party, often through insurance or contractual arrangements, while avoidance eliminates the risk by discontinuing the activity or system that creates the exposure.