{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework: The NIST Cybersecurity Framework (CSF)","title":"ID.RA-05 - Understanding Inherent Cybersecurity Risks","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/2db13bc6\"></iframe>","width":"100%","height":180,"duration":1175,"description":"ID.RA-05 uses data on threats, vulnerabilities, likelihoods, and impacts to assess inherent risk—the risk before controls are applied—and prioritize responses. This involves developing threat models to understand risks to critical assets and guide mitigation strategies. It ensures that risk management focuses on the most pressing dangers.\nThis subcategory supports strategic decision-making by linking risk analysis to resource investments, emphasizing high-probability, high-impact scenarios. It provides a structured approach to weighing risks against organizational tolerances. ID.RA-05 drives a risk-based prioritization of cybersecurity efforts.","thumbnail_url":"https://img.transistorcdn.com/ZQAUShkq6bmReWtsoCApAiEqnASSjulPAjN3RZCtsFI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTE2/ZTU4ZDc5YjBhMjRj/MDkxMTllN2RmZDU5/YmU2My5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}