<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1c1bb2bea">
    <name type="corporate">
         <namePart>United States Government Publishing Office</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
              <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
         <role>
              <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
              <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
         <namePart>United States</namePart>
         <namePart>Commerce Department</namePart>
         <namePart>National Institute of Standards and Technology (NIST)</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
         <description>Government Organization</description>
    </name>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
         <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
         <collectionCode>GOVPUB</collectionCode>
         <category>Executive Agency Publications</category>
         <branch>executive</branch>
         <dateIngested>2023-10-27</dateIngested>
    </extension>
    <originInfo>
         <publisher>Commerce Department</publisher>
         <dateIssued encoding="w3cdtf">2022-02-10</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <note type="source content type">deposited</note>
         <digitalOrigin>born digital</digitalOrigin>
         <extent>43 digital object pages</extent>
    </physicalDescription>
    <classification authority="sudocs">C 13.</classification>
    <identifier type="uri">https://www.govinfo.gov/app/details/GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e</identifier>
    <identifier type="local">P0b002ee1c1bb2bea</identifier>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST Interagency or Internal Reports</title>
        </titleInfo>
    </relatedItem>
    <identifier type="ILS system id">on1389889975</identifier>
    <identifier type="oclc">(OCoLC)1389889975</identifier>
    <recordInfo>
         <recordContentSource authority="marcorg">DGPO</recordContentSource>
         <recordCreationDate encoding="w3cdtf">2023-10-27</recordCreationDate>
         <recordChangeDate encoding="w3cdtf">2026-06-27</recordChangeDate>
         <recordIdentifier source="DGPO">GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e</recordIdentifier>
         <recordOrigin>machine generated</recordOrigin>
         <languageOfCataloging>
              <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    <accessCondition type="GPO scope determination">fdlp</accessCondition>
    <extension>
         <docClass>C13</docClass>
         <accessId>GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e</accessId>
         <uniqueId>4265be69316bbf3d937ee195ec010d1e</uniqueId>
         <ACCode>GOVPUB</ACCode>
         <fedPubName>NIST Interagency or Internal Reports</fedPubName>
         <field name="Note">NOTE: THE “DATE ISSUED” ABOVE MAY DEFAULT TO JANUARY 1ST OF A GIVEN YEAR. TO THE VIEW THE MOST ACCURATE DATE OF ISSUE, REVIEW THE TITLE PAGE OF THE PUBLICATION.</field>
         <description>Interim or final reports on work performed by NIST for outside sponsors (both government and non-government). May also report results of NIST projects of transitory or limited interest, including those that will be published subsequently in more comprehensive form.</description>
         <agency abbrev="NIST">National Institute of Standards and Technology</agency>
         <resultsLineTwoText>Commerce Department. National Institute of Standards and Technology. 2022</resultsLineTwoText>
         <dateIssued>2022-02-10</dateIssued>
    </extension>
    <location>
         <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e</url>
         <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e/pdf/GOVPUB-C13-4265be69316bbf3d937ee195ec010d1e.pdf</url>
    </location>
    <titleInfo>
         <title>Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight</title>
    </titleInfo>
    <subject>
         <topic>Computer security</topic>
         <topic>Cybersecurity risk management</topic>
         <topic>Cybersecurity risk measurement</topic>
         <topic>Cybersecurity risk register (CSRR)</topic>
         <topic>Enterprise risk management (ERM)</topic>
         <topic>Key performance indicator (KPI)</topic>
         <topic>Key risk indicator (KRI)</topic>
         <topic>Risk acceptance</topic>
         <topic>Risk aggregation</topic>
         <topic>Risk avoidance</topic>
         <topic>Risk conditioning</topic>
         <topic>Risk management</topic>
         <topic>Risk mitigation</topic>
         <topic>Risk optimization</topic>
         <topic>Risk prioritization</topic>
         <topic>Risk response</topic>
         <topic>Risk sharing</topic>
         <topic>Risk transfer</topic>
    </subject>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">creator</roleTerm>
        </role>
    </name>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
    </name>
    <name type="personal">
         <namePart>Ivy, Nahla.</namePart>
    </name>
    <name type="personal">
         <namePart>Barrett, Matthew.</namePart>
    </name>
    <name type="personal">
         <namePart>Witte, Greg.</namePart>
    </name>
    <name type="personal">
         <namePart>Gardner, R. K.</namePart>
    </name>
    <name type="corporate">
         <namePart>National Institute of Standards and Technology (U.S.)</namePart>
         <namePart>Material Measurement Laboratory</namePart>
    </name>
    <originInfo>
         <place>
              <placeTerm authority="marccountry" type="code">mdu</placeTerm>
        </place>
         <publisher>U.S. Dept. of Commerce, National Institute of Standards and Technology</publisher>
         <dateIssued>2022-02-10.</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <extent>1 online resource (43 pages) : illustrations (color)</extent>
    </physicalDescription>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">technical report</genre>
    <language>
         <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </language>
    <abstract>This document is the third in a series that supplements NIST Interagency/Internal Report (NISTIR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding the enterprise application of cybersecurity risk information; the previous documents, NISTIRs 8286A and 8286B, provided details regarding stakeholder risk direction and methods for assessing and managing cybersecurity risk in light of enterprise objectives. NISTIR 8286C describes how information, as recorded in cybersecurity risk registers (CSRRs), may be integrated as part of a holistic approach to ensuring that risks to information and technology are properly considered for the enterprise risk portfolio. This cohesive understanding supports an enterprise risk register (ERR) and enterprise risk profile (ERP) that, in turn, support the achievement of enterprise objectives.</abstract>
    <note type="statement of responsibility">Stephen Quinn; Nahla Ivy; Matthew Barrett; Greg Witte; R. K. Gardner.</note>
    <note>February 2022.</note>
    <note>Title from PDF title page (viewed January 4, 2023).</note>
    <note type="bibliography">Includes bibliographical references.</note>
    <note type="venue">Approved by the NIST Editorial Review Board on 2022-09-20</note>
    <note type="system details">Mode of access: World Wide Web.</note>
    <note type="system details">Systems requirements: Adobe Acrobat PDF reader.</note>
    <subject authority="lcsh">
         <topic>Computer security</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Risk management</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk management</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk measurement</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk register (CSRR)</topic>
    </subject>
    <subject>
         <topic>Enterprise risk management (ERM)</topic>
    </subject>
    <subject>
         <topic>Key performance indicator (KPI)</topic>
    </subject>
    <subject>
         <topic>Key risk indicator (KRI)</topic>
    </subject>
    <subject>
         <topic>Risk acceptance</topic>
    </subject>
    <subject>
         <topic>Risk aggregation</topic>
    </subject>
    <subject>
         <topic>Risk avoidance</topic>
    </subject>
    <subject>
         <topic>Risk conditioning</topic>
    </subject>
    <subject>
         <topic>Risk mitigation</topic>
    </subject>
    <subject>
         <topic>Risk optimization</topic>
    </subject>
    <subject>
         <topic>Risk prioritization</topic>
    </subject>
    <subject>
         <topic>Risk response</topic>
    </subject>
    <subject>
         <topic>Risk sharing</topic>
    </subject>
    <subject>
         <topic>Risk transfer</topic>
    </subject>
    <relatedItem type="series">
         <titleInfo>
              <title>NISTIR; NIST IR; NIST interagency report; NIST internal report; 8286C</title>
        </titleInfo>
    </relatedItem>
    <location>
         <url displayLabel="electronic resource" usage="primary display">https://doi.org/10.6028/NIST.IR.8286C</url>
    </location>
    <titleInfo type="alternative">
         <title>Staging cybersecurity risks for enterprise risk management and governance oversight</title>
    </titleInfo>
    <extension>
         <searchTitle>
              <title>Staging cybersecurity risks for enterprise risk management and governance oversight</title>
        </searchTitle>
    </extension>
</mods>