Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

RA-10 — Threat Hunting

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
1Parameters
0Baseline memberships
3Assessment methods

RA — Risk Assessment · NIST SP 800-53 Release 5.2.0

Official NIST control content

Control statement

  1. a.Establish and maintain a cyber threat hunting capability to:
    1. 1.Search for indicators of compromise in organizational systems; and
    2. 2.Detect, track, and disrupt threats that evade existing controls; and
  2. b.Employ the threat hunting capability [Organization-defined: frequency].
Official NIST discussion

Discussion

Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The objective is to track and disrupt cyber adversaries as early as possible in the attack sequence and to measurably improve the speed and accuracy of organizational responses. Indications of compromise include unusual network traffic, unusual file changes, and the presence of malicious code. Threat hunting teams leverage existing threat intelligence and may create new threat intelligence, which is shared with peer organizations, Information Sharing and Analysis Organizations (ISAO), Information Sharing and Analysis Centers (ISAC), and relevant government departments and agencies.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency at which to employ the threat hunting capability is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Threat Hunting as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to risk framing, threat and vulnerability analysis, impact, criticality, and response decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • risk assessments and threat models
  • vulnerability findings and prioritization records
  • supply-chain risk assessments
  • risk response and acceptance decisions

Common failure patterns

  • risk registers detached from technical evidence
  • vulnerability severity treated as business impact
  • assessments not updated after material change
  • accepted risks have no owner or expiration

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. RA-10a.
    1. RA-10a.01a cyber threat capability is established and maintained to search for indicators of compromise in organizational systems;
    2. RA-10a.02a cyber threat capability is established and maintained to detect, track, and disrupt threats that evade existing controls;
  2. RA-10b.the threat hunting capability is employed [Organization-defined: frequency].

Examine

  • Risk assessment policy
  • assessment reports
  • audit records/event logs
  • threat hunting capability
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with threat hunting responsibilities
  • system/network administrators
  • organizational personnel with security responsibilities

Test

  • Organizational processes for assessments and audits
  • mechanisms/tools supporting and/or implementing threat hunting capabilities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Source record

Authoritative sources