Skip to content
ControlVerdict
RA.L2-3.11.1addresses
RA.L2-3.11.1Risk Assessments
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
  • [a]

    the frequency to assess risk to organizational operations, organizational assets, and individuals is defined; and
  • [b]

    risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.

View full control

Annual risk assessment on the budget calendar, plus a written trigger list for out-of-cycle re-scoring

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. Only 1 verdict so far.Last verdict Aug 2, 2026

Implementation

AO coverage. Addresses both Risk Assessments objectives: the frequency to assess risk to operations, assets, and individuals is defined, and the assessment is actually performed at that frequency for the systems that process, store, or transmit CUI.

The defined frequency, and where it is written. The risk management policy states a full assessment annually, scheduled deliberately in the first quarter so its output lands before the capital budget is set — a risk assessment that finishes after the money is allocated produces a list nobody can act on. The policy also names the shorter cadence: a 30-minute quarterly review of the top ten risks and the trigger log, which is not a full assessment and is not claimed as one.

Triggers for an out-of-cycle assessment. Waiting a year after a material change is how a current-looking document goes stale, so the policy enumerates triggers: award of a contract with new CUI categories or a new flow-down, a change to the assessment boundary, adoption of a SaaS service that will hold CUI, a significant incident or near-miss, an adverse finding from a customer or C3PAO review, a change of managed service provider, and installation of new shop-floor equipment with network connectivity. A trigger fires a scoped re-assessment of the affected area within 30 days. Triggers and their dispositions are logged, including the ones we decided did not warrant re-assessment and why, because an empty trigger log reads as a process nobody runs.

Scope, expressed in asset categories. The assessment covers the four asset categories we maintain in the inventory of record: CUI assets, security protection assets, contractor risk managed assets, and specialized assets — for us the two networked CNC controllers and the CMM in the inspection room. Risk to individuals is treated explicitly rather than folded into business impact: the personal consequences of a compromise of the HR and screening records held alongside program data get their own register entries.

Method. Likelihood and impact are scored one through five against written anchors, so a four for likelihood means something specific — observed in our environment or in our sector within the last year — instead of meaning whoever spoke loudest thought it felt likely. Impact anchors are stated in terms we can defend: contract-level consequences, recovery cost bands, production downtime in shifts, and CUI exposure scope. Threat inputs come from public advisory feeds, the sector sharing group, and our own incident history; vulnerability inputs come from scan trend data and the open POA&M. Two half-day facilitated workshops produce the register, with named participation from the ISSO, IT lead, operations manager, contracts, and quality — operations and contracts attend because they are the only people who can size production and contractual impact honestly.

Output that has to go somewhere. Every register entry carries a scored risk, a named accountable owner who is not the ISSO by default, and a treatment decision of mitigate, accept, transfer, or avoid. Mitigations become POA&M items with dates and a funding line. Acceptances are signed by the accountable executive and carry an expiry no longer than twelve months, so an accepted risk is revisited rather than quietly becoming permanent. The register version and date are recorded in the SSP so an assessor can tell which assessment the current control set reflects.

Maintenance. Quarterly top-ten and trigger-log review with the ISSO and IT lead. Annual review of the scoring anchors themselves, since anchors calibrated to a smaller company drift as revenue and headcount change. Prior register versions retained so year-over-year movement is visible.

Accepted gaps. The scoring is qualitative and consensus-based; there is no quantitative loss modeling, and we do not present the numbers as if there were. Supply chain risk is assessed only for tier-one subcontractors who receive CUI — lower tiers are covered by flow-down language and not by our own analysis. Both limitations are stated in the assessment report rather than left for an assessor to discover.

What the evidence looks like

  • Risk management policy section stating the annual frequency and the enumerated out-of-cycle triggers
  • Scoring rubric with written likelihood and impact anchors
  • Current risk register export with scores, owners, treatment decisions, and dates
  • Workshop agenda, attendance record, and the input list used (prior register, POA&M, scan trends, incident log)
  • Trigger log showing at least one fired trigger and the resulting scoped re-assessment
  • Signed risk acceptance memo with an expiry date, and the POA&M items traceable to register entries

Environment

90-person precision machine shop. The prior risk assessment was a one-time PDF written to win a contract award in 2019 and never touched again, so the first fix was making the cadence real rather than aspirational.

Tools

1 rating on this revision

  • AlignedControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

    Across the finish line

    Risk assessment cadence and output artifacts are concrete.

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.