NIST 800-171 Controls · Risk Assessment
RA.2.001 — Periodically Assess Risk
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
What RA.2.001 means in plain English
At least once a year, sit down and think about what could go wrong with your computers and data. What if an employee clicks a phishing link? What if your server hard drive dies? What if a disgruntled ex-employee still has a password? Write down these risks, rate how likely they are and how bad the impact would be, and then decide what you are doing about each one. This does not have to be fancy — a spreadsheet with columns for threat, likelihood, impact, and mitigation works fine.
The assessment question
“Do you perform a documented risk assessment at least annually that identifies threats and vulnerabilities to your systems and CUI, rates their likelihood and impact, and documents planned mitigations?”
How to implement RA.2.001
- Download the NIST SP 800-30 risk assessment template or create a spreadsheet with columns: Threat Source, Threat Event, Vulnerability, Likelihood (Low/Medium/High), Impact (Low/Medium/High), Risk Level, and Planned Mitigation.
- Schedule a half-day annual risk assessment meeting with your key staff. Walk through each threat category: insider threats, external hackers, natural disasters, equipment failure, supply chain issues.
- For each identified risk, assign an owner (the person responsible for the mitigation) and a target completion date. Document this in your risk register spreadsheet.
- Review and update the risk assessment whenever there is a significant change — new system, new contract, new location, or after a security incident.
- Store the completed risk assessment with your compliance documentation and reference it in your System Security Plan.
Evidence your assessor will ask for
- Completed risk assessment document or risk register with identified threats and vulnerabilities
- Evidence of likelihood and impact ratings for each identified risk
- Mitigation plans with assigned owners and target dates
- Evidence the risk assessment was reviewed or updated within the past 12 months
- Meeting notes or attendance from the annual risk assessment session
Does AI prompt monitoring help with this control? Honestly, no.
RA.2.001 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Risk Assessment controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.