U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

NIST IR 8286A (2nd Public Draft)

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management (ERM)

Date Published: July 2021
Comments Due: August 6, 2021 (public comment period is CLOSED)
Email Questions to: nistir8286@nist.gov

Author(s)

Kevin Stine (NIST), Stephen Quinn (NIST), Nahla Ivy (NIST), Larry Feldman (Huntington Ingalls Industries), Gregory Witte (Huntington Ingalls Industries), Robert Gardner (New World Technology Partners)

Announcement

This report provides a more in-depth discussion of the concepts introduced in NISTIR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This IR8286 series document is intended to help organizations better implement cybersecurity risk management (CSRM) as an integral part of ERM – both taking its direction from ERM and informing it. The increasing frequency, creativity, and severity of cybersecurity attacks mean that all enterprises should ensure that cybersecurity risk is receiving appropriate attention within their ERM programs and that the CSRM program is anchored within the context of ERM.

This second draft specifically incorporates feedback received during the first public comment period and provides improved editorial updates and graphics to better illustrate the intersection of cybersecurity and enterprise risk management. With the inclusion of an example risk detail report (RDR) template, this draft more clearly demonstrates how risks are summarized in the risk register using methods for populating the RDR. The language surrounding activities – including metrics and communication at each level of the enterprise – has also been updated, and the topics of privacy and supply chain have been introduced for planned future treatment.

A companion document, NISTIR 8286B: Prioritizing Cybersecurity Risk for Enterprise Risk Management, will be available for review and comment in the coming weeks.

Also, see the related publications:

NOTE: A call for patent claims is included on page iii of this draft.  For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Abstract

Keywords

cybersecurity risk management; cybersecurity risk measurement; cybersecurity risk register; enterprise risk management (ERM); enterprise risk profile
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8286A-draft2
Download URL

Supplemental Material:
See NISTIR 8286 Supplemental Material

Other Parts of this Publication:
IR 8286
IR 8286B

Document History:
12/14/20: IR 8286A (Draft)
07/06/21: IR 8286A (Draft)
11/12/21: IR 8286A (Final)

Topics

Security and Privacy

risk management, security measurement

Applications

enterprise