RA.L2-3.11.3[c] – Determine if a risk assessment process is used.
This objective confirms that your organization’s risk assessment process isn’t just documented — it’s actively used to evaluate risks to Controlled Unclassified Information (CUI). You must demonstrate that your team follows the process consistently and that results lead to meaningful actions.
RA.L2-3.11.1[b] – Examine documentation to confirm risks associated with the processing, storage, and transmission of CUI are identified.
This objective ensures your organization has formally documented the risks related to how Controlled Unclassified Information (CUI) is processed, stored, and transmitted. Assessors will expect to see evidence that risks were identified, evaluated, and tied to specific systems or workflows.
RA.L2-3.11.3[b] – Examine documentation to confirm a risk assessment process is identified and implemented.
This objective ensures your organization has formally documented and is actively using a risk assessment process to evaluate potential threats to Controlled Unclassified Information (CUI). Assessors will expect to see a defined, repeatable process in writing—and evidence that it’s been followed.
RA.L2-3.11.2[a] – Identify risk responses for identified risks.
This objective requires your organization to define how you will respond to each identified risk that could impact the processing, storage, or transmission of Controlled Unclassified Information (CUI). Risk responses must be intentional, documented, and appropriate to the severity of the risk.
RA.L2-3.11.1[a] – Identify risks associated with the processing, storage, and transmission of CUI.
This objective requires your organization to identify security risks related to how Controlled Unclassified Information (CUI) is processed, stored, or transmitted within your systems. This is the foundation for proactive risk management and CUI protection.
RA.L2-3.11.2[c] – Determine if risk responses are implemented.
This objective confirms that your organization is not only documenting risk responses but actively carrying them out. Whether the decision was to mitigate, accept, transfer, or avoid a risk, this control verifies that those actions are being followed and tracked—especially for risks related to Controlled Unclassified Information (CUI).
RA.L2-3.11.3[a] – Identify and implement a risk assessment process.
This objective requires your organization to identify and establish a formal risk assessment process that guides how you evaluate, document, and respond to risks that may affect the security of Controlled Unclassified Information (CUI).
RA.L2-3.11.4 – Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
This control requires your organization to create and maintain a System Security Plan (SSP) that documents key details about how Controlled Unclassified Information (CUI) is protected. The SSP must be reviewed and updated regularly to reflect changes in systems, operations, or security controls.
3.11.1 – Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI
This control requires organizations to conduct regular risk assessments to identify, evaluate, and document threats to systems and processes that store or handle Controlled Unclassified Information (CUI). Read the full blog breakdown of 3.11.1
3.11.3 – Remediate vulnerabilities in accordance with risk assessments
This control requires organizations to fix identified vulnerabilities based on the risk they pose, not just the order they were found or how easy they are to fix. Remediation efforts must be risk-based, prioritized, and tracked. Read the full blog breakdown of 3.11.3