What RA-6 says
Control RA-6 in NIST Special Publication 800-53 Revision 5 sits in the Risk Assessment family and directs organizations to employ a technical surveillance countermeasures survey at organization-defined locations, either on an organization-defined frequency or when organization-defined events or indicators occur.
The supplemental guidance describes a TSCM survey as a service provided by qualified personnel to detect the presence of technical surveillance devices and hazards, and to identify technical security weaknesses that could support a technical penetration of the surveyed facility. The survey output feeds the organization's broader risk assessments — which is exactly how a mature program should treat it.
Who has to care
RA-6 is not in the standard FedRAMP Low, Moderate, or High baselines — it is an optional control selected where the risk profile warrants it. In practice it appears in system security plans for facilities handling classified information, in agency overlays, and in contracts where classified or highly sensitive discussions occur in defined spaces. Defense and intelligence community contractors see it most often.
For commercial organizations, RA-6 matters as the reference model: when a customer, auditor, or insurer asks what standard your counter-surveillance program follows, RA-6 with its defined locations, defined frequency, and defined trigger events is the recognized federal vocabulary to answer in.
Satisfying RA-6 in practice
Three parameters do the work. Locations: identify the spaces where the sensitive discussions and processing actually happen — conference rooms used for classified or proprietary meetings, executive offices, SCIF-adjacent spaces, and rooms exposed to visitor or contractor traffic. Frequency: set a periodic cadence proportionate to threat, commonly quarterly for high-threat spaces and semiannual for standard sensitive areas. Events: define the indicators that trigger an unscheduled survey — suspected leaks, renovations, unescorted third-party access, and significant personnel departures.
Then document like an assessor will read it, because one will. Each survey needs a dated record of scope, method, equipment class, findings, and disposition. Tie discovered devices or anomalies into your incident response process under IR family controls, and feed residual risk back into RA-3 risk assessments.
Related controls worth mapping
RA-6 rarely stands alone. RA-3 provides the risk assessment the survey informs. PE-3 governs physical access to the spaces being protected, and PE-6 covers monitoring physical access — both reduce the opportunity for device placement that RA-6 then verifies. SC-42, on sensor capability and data, is relevant where microphones and cameras in conference technology create standing collection risk. A short mapping table in your system security plan connecting these controls reads as maturity to any assessor.