---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Categorize targets

# Categorize targets {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Within the NIST RMF
application, the Categorize section facilitates the categorization of
targets through a preliminary risk assessment and an impact analysis.
Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://www.servicenow.com/docs/s5uGqPgL9j543l_fdj99WQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").  
First, a target is created from an entity or an entity type. The application flow begins at Impact Analysis. The user locates a target and sets it up for use with NIST RMF providing basic information. Next, the user performs a preliminary risk assessment determining the potential impact value on each of the following parameters: Confidentiality, Integrity, and Availability. The highest impact rating of these values determines the Impact value.  
Note:  
The user can override the Impact value, as necessary.

The Impact value is used to identify the baseline security policy
statements recommended for the target, based on the NIST 800-53.r4 special publications catalog.
The user reviews the baseline security policy statements and implements security controls for
that target (for example, Profile). The standard approach is outlined in the Policy and Compliance Management
application.
* **[Generate target from profile or entity type](https://www.servicenow.com/docs/Qk_e0gmr0wHKaWrjVPBKdg)**   
  Generate a target record for a profile to track NIST RMF attributes.
* **[Set up a target for use with NIST RMF](https://www.servicenow.com/docs/J9QTE5NqWhsPJCYNDvafDA)**   
  Set up a target and populate the basic information.
* **[Perform preliminary risk assessment and impact analysis](https://www.servicenow.com/docs/qNCmdFz7DWVCANqAGZzHTQ)**   
  Perform a preliminary risk assessment and impact analysis of the target.
* **[Monitor the NIST RMF Categorize Overview](https://www.servicenow.com/docs/qlnq_LKsDb~69mwRr7SoYg)**   
  The NIST RMF categorization activity dashboard provides insights into the overall status of the target.

