> For the complete documentation index, see [llms.txt](https://calvin-lai.gitbook.io/calvin-lai-security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://calvin-lai.gitbook.io/calvin-lai-security/risk-management/it-risk-and-control-library-policy-and-procedure/assessment-level.md).

# Assessment Level

In Information Security Risk Assessment (ISRA), changes are categorized into three levels: **Level 1**, **Level 2**, and **Level 3**. These levels dictate the scrutiny, controls, criticality, risk review, and quality checks. This tiered approach streamlines processes while managing risks effectively, aligning with NIST SP 800-53 (e.g., CM-3 for Configuration Change Control and RA-3 for Risk Assessment).

| Change Level | Criteria (Key Triggers)                                                                                                                                                                                      | Applicable Controls                      | Criticality                                                                                                                                                                 | Risk Assessment Review                                                                                                                                                                    | NIST Alignment                                                                   | Quality Check                |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | ---------------------------- |
| **Level 1**  | <p>- New/modified confidential/PII<br>- Asset reclassification to critical<br>- Cloud/third-party additions<br>- Major process/architecture changes</p>                                                      | ISRA questionnaire + full/sample review  | <p>High: Large-scale projects with major operational/financial/regulatory impact (e.g., new systems, cloud services).<br>Medium: Smaller projects with similar impacts.</p> | <p>High: Full ITRA review post-PM confirmation.<br>Medium: Sample-based review.<br><br>Sample Sizes:<br><=2 risks/controls: 1 sample<br>3-12: 2<br>13-52: 5<br>53-365: 20<br>>365: 25</p> | CM-3 (full change control), RA-3 (comprehensive assessment), SA-10 (config mgmt) | Quarterly (all closed ISRAs) |
| **Level 2**  | <p>Pre-approved systems with routine updates:<br>- UI improvements<br>- Algorithm optimizations<br>- Bug/security fixes<br>- Feature additions without redesign<br><br>Approved: ITWS FO Monthly Release</p> | Pre-defined Standard Change control list | Low                                                                                                                                                                         | N/A (Direct sign-off)                                                                                                                                                                     | CM-3 (baseline change control)                                                   | Quarterly (all closed ISRAs) |
| **Level 3**  | <p>Minimal impact (triage summary):<br>- No criticality uplift<br>- No PII changes<br>- No third-party/process/architecture shifts</p>                                                                       | Pre-defined Brief Change control list    | Low                                                                                                                                                                         | N/A (Direct sign-off)                                                                                                                                                                     | CM-3 (minimal documentation)                                                     | Quarterly (all closed ISRAs) |
