unified
UC-RISK-18 — Categorize systems and components by impact and criticality
Systems and the information they process, store, and transmit are categorized based on the potential impact of a loss of confidentiality, integrity, and availability, with categorization decisions documented and approved by accountable officials. Criticality analysis identifies critical system components, functions, and dependencies so protection and resilience investments are prioritized accordingly.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-18
- title
- Categorize systems and components by impact and criticality
- statement
- Systems and the information they process, store, and transmit are categorized based on the potential impact of a loss of confidentiality, integrity, and availability, with categorization decisions documented and approved by accountable officials. Criticality analysis identifies critical system components, functions, and dependencies so protection and resilience investments are prioritized accordingly.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- RA-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- RA-9
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-RISK-18 — Categorize systems and components by impact and criticality maps_to RA-9 — Criticality Analysis
- framework
- nist-800-53
- control_id
- RA-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-18 — Categorize systems and components by impact and criticality mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Impact/criticality categorization prioritizes protective and resilience investment on high-value systems: necessary context, not the operative defense (inventory-type enabler).
- System Categorization, Security Planning & Authorization operates UC-RISK-18 — Categorize systems and components by impact and criticality
- UC-RISK-18 — Categorize systems and components by impact and criticality maps_to RA-2 — Security Categorization
- framework
- nist-800-53
- control_id
- RA-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- System and Third-Party Risk Review operates UC-RISK-18 — Categorize systems and components by impact and criticality
- UC-RISK-18 — Categorize systems and components by impact and criticality mitigates Absent or untested business continuity / disaster recovery plan
- strength
- related
- rationale
- Criticality analysis identifies critical components, functions and dependencies, informing which processes continuity/recovery planning must prioritize.
- NIST RMF System Authorization (ATO) Cycle oversees UC-RISK-18 — Categorize systems and components by impact and criticality