NIST 800-53 r5 · Controls catalogue · Family RA
RA-7Risk Response
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Missing authorization is frequently identified by security assessments; organizational risk-response procedures drive remediation, directly limiting an attacker's ability to invoke protected functionality. |
CWE-284 | Improper Access Control | 6,900+ | Findings of improper access control are routine outputs of audits and assessments; mandated response ensures the weaknesses are corrected before they can be exploited at scale. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Incorrect permission assignments on critical resources are typical audit findings; responding to them per risk tolerance removes the excessive privileges that enable exploitation. |
CWE-693 | Protection Mechanism Failure | 700+ | When assessments or monitoring reveal that protection mechanisms are ineffective or bypassed, the required risk-response action directly restores or strengthens those mechanisms. |
CWE-657 | Violation of Secure Design Principles | 20 | Audits and assessments commonly surface violations of secure design principles; formal risk-response processes ensure such findings are remediated according to risk tolerance, reducing the window for exploitation. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||