RA-4 Risk Assessment

RA-4 Withdrawn / Not Selected in Current Baseline

Low Risk Easy Low Cost

RA-4 is not an active NIST SP 800-53 Revision 5 base control. The identifier appears in some legacy catalogs or as an unused numbering slot within the Risk Assessment family, but organizations should not treat RA-4 as a selectable Rev. 5 baseline requirement. Historically this ID referred to "Risk Assessment Update." RA-4 (risk assessment update) was withdrawn; ongoing update expectations are incorporated into the active risk assessment process under RA-3 and related continuous monitoring. Healthcare security programs, System Security Plans (SSPs), and HIPAA Security Rule mappings should cite the related active controls instead of inventing implementation evidence for RA-4.

Control Objective

Do not select RA-4 as an active Rev. 5 baseline control; document withdrawn/unused status and satisfy the underlying intent through the related active NIST controls listed for this identifier.

Implementation Guidance

  1. Confirm in NIST SP 800-53 Rev. 5 (and overlays you use) that RA-4 is withdrawn or not defined as a base control.
  2. Mark RA-4 as Not Selected / Withdrawn in the SSP control catalog with a short rationale.
  3. Map any legacy checklist rows that still cite RA-4 to related active controls: RA-3, RA-5, CA-7, PM-9.
  4. Update HIPAA Security Rule crosswalks so assessors are pointed at live AC/AU/CM/IA/RA/SC/SI controls.
  5. Remove RA-4 from vulnerability scanners, GRC templates, and RFP questionnaires that imply it is current.
  6. If a partner still asks for RA-4, provide the withdrawn note plus evidence against the successor controls.
  7. Keep a one-page family appendix for auditors who search by legacy ID.
  8. Re-check after catalog upgrades so placeholders are not reintroduced as "open findings."

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

SSP cleanup after catalog import

A GRC tool imported legacy IDs including RA-4. The HIPAA compliance team marks RA-4 Not Selected / Withdrawn and links evidence to RA-3, RA-5, CA-7, PM-9 so the control does not appear as an open gap.

Assessor asks for RA-4 evidence

An external assessor’s workbook still lists RA-4. The organization provides the Rev. 5 withdrawn/unused explanation and walks the assessor through related active controls rather than fabricating RA-4-specific procedures.

Vendor questionnaire hygiene

A BA security questionnaire requires "implement RA-4." Security responds that RA-4 is not an active Rev. 5 base control and maps answers to RA-3, RA-5, CA-7, PM-9, avoiding false attestation.

Best Practices

  • Prefer Rev. 5 (or your authorized overlay) as the source of truth for control IDs.
  • Record Not Selected with rationale for withdrawn/unused IDs.
  • Keep a legacy-ID → active-control map for assessors.
  • Do not invent policies solely to "satisfy" withdrawn numbers.
  • Align HIPAA mappings to active controls only.
  • Purge withdrawn IDs from automated scanners and scorecards.

Common Gaps & Violations

  • Leaving RA-4 as "Partially Implemented" with empty evidence.
  • Writing boilerplate procedures for a control that does not exist in Rev. 5.
  • Failing HIPAA assessments because the crosswalk still keys off withdrawn IDs.
  • Vendors claiming RA-4 certification as if it were current.
  • Placeholder title "Risk Assessment" left unpublished with empty use cases.

Required Documentation

  • SSP entry: RA-4 Not Selected / Withdrawn (rationale)
  • Legacy ID mapping table to active controls
  • Updated HIPAA–NIST crosswalk pages
  • Assessor FAQ / appendix for withdrawn IDs
  • Change ticket removing RA-4 from GRC open items

How to Test & Validate

  1. Search SSP and GRC for RA-4; expect Not Selected / Withdrawn, not Open.
  2. Confirm related active controls RA-3, RA-5, CA-7, PM-9 have owners and evidence.
  3. Spot-check HIPAA crosswalk for live control IDs only.
  4. Verify scanners/questionnaires do not score RA-4 as failed.
  5. Ask a sample assessor question path: legacy ID → successor evidence.

Audit Considerations

Auditors may still search by historical numbers. A clear withdrawn/unused statement plus mapped evidence on active controls is stronger than empty placeholder pages or forced "implementation" narratives for RA-4.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis / Risk Management — map safeguards to controls that actually exist and are operated.
  • 164.306 Security Standards: General Rules — reasonable and appropriate measures; do not chase withdrawn catalog slots.
  • 164.316 Policies and Procedures — documentation should reflect the current control baseline used by the organization.
  • Assessment practice: HIPAA evaluations should map to active NIST SP 800-53 Rev. 5 controls (and HIPAA implementation specifications), not withdrawn IDs like RA-4.

Compliance Tips

  • Add RA-4 to a "withdrawn/unused" appendix rather than the implementable baseline list.
  • Train GRC admins not to reopen withdrawn IDs after tool upgrades.
  • When in doubt, implement and evidence RA-3, RA-5, CA-7, PM-9.

Frequently Asked Questions

Should we implement RA-4 for HIPAA?

No. RA-4 is not an active Rev. 5 base control. Satisfy the intent through related active controls (RA-3, RA-5, CA-7, PM-9) and map those to the HIPAA Security Rule.

Why is RA-4 in our database?

Legacy catalogs and sequential family numbering often retain withdrawn or unused slots. This page documents that status so thin/placeholder content is not mistaken for a live requirement.

What do we show an assessor who insists on RA-4?

Show the Not Selected / Withdrawn rationale and the evidence package for the successor/related controls.

References & Resources

  • NIST SP 800-53 Rev. 5 control catalog (withdrawn / not defined entries)
  • Related active controls: RA-3, RA-5, CA-7, PM-9
  • NIST SP 800-53B control baselines (confirm non-selection)

Need Help Implementing RA-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.