RA-7: Risk Response

NIST Baseline: Low 

Privacy Baseline:  Yes 

DIR Required By:  07/20/2023 

Review Date:  07/31/2024 

  1. The information resource owner or custodian shall respond to findings from security and privacy assessments, monitoring, and audits in accordance with university accepted risk tolerance and system criticality. 

References/Additional Resources

FIPS 199 

FIPS 200 

SP 800-30 

SP 800-37 

SP 800-39 

SP 800-160-1 

1 TAC § 202.25(4) 

1 TAC §202.75(4)