This document is the second in a series that supplements NIST Interagency/Internal Report (NISTIR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional detail regarding the enterprise application of cybersecurity risk information; the previous document, NISTIR 8286A, provided detail regarding stakeholder risk guidance and risk identification and analysis. This second publication describes the need for determining the priorities of each of those risks in light of their potential impact on enterprise objectives, as well as options for properly treating that risk. This report describes how risk priorities and risk response information are added to the cybersecurity risk register (CSRR) in support of an overall enterprise risk register. Information about the selection of and projected cost of risk response will be used to maintain a composite view of cybersecurity risks throughout the enterprise, which may be used to confirm and, if necessary, adjust risk strategy to ensure mission success.
Document Citations
Citations are generated automatically from bibliographic data
as a convenience and may not be complete or accurate.
Chicago
National Institute of Standards and Technology (NIST), Commerce Department. "Prioritizing Cybersecurity Risk for Enterprise Risk Management". Government. Commerce Department, February 10, 2022. https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89
APA
National Institute of Standards and Technology (NIST), Commerce Department. (2022, February 10). Prioritizing Cybersecurity Risk for Enterprise Risk Management. [Government]. Commerce Department. https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89
MLA
National Institute of Standards and Technology (NIST), Commerce Department. Prioritizing Cybersecurity Risk for Enterprise Risk Management. Commerce Department, (10 Feb 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89
Bluebook
National Institute of Standards and Technology (NIST), Commerce Department, Prioritizing Cybersecurity Risk for Enterprise Risk Management, GovInfo, (February 10, 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89