<mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="P0b002ee1c1bb2bf0">
    <name type="corporate">
         <namePart>United States Government Publishing Office</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
              <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
         <role>
              <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
              <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
         <namePart>United States</namePart>
         <namePart>Commerce Department</namePart>
         <namePart>National Institute of Standards and Technology (NIST)</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
         <description>Government Organization</description>
    </name>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">author</roleTerm>
              <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
         <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
         <collectionCode>GOVPUB</collectionCode>
         <category>Executive Agency Publications</category>
         <branch>executive</branch>
         <dateIngested>2023-10-27</dateIngested>
    </extension>
    <originInfo>
         <publisher>Commerce Department</publisher>
         <dateIssued encoding="w3cdtf">2022-02-10</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <note type="source content type">deposited</note>
         <digitalOrigin>born digital</digitalOrigin>
         <extent>45 digital object pages</extent>
    </physicalDescription>
    <classification authority="sudocs">C 13.</classification>
    <identifier type="uri">https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89</identifier>
    <identifier type="local">P0b002ee1c1bb2bf0</identifier>
    <relatedItem type="series">
         <titleInfo>
              <title>NIST Interagency or Internal Reports</title>
        </titleInfo>
    </relatedItem>
    <identifier type="ILS system id">on1389889996</identifier>
    <identifier type="oclc">(OCoLC)1389889996</identifier>
    <recordInfo>
         <recordContentSource authority="marcorg">DGPO</recordContentSource>
         <recordCreationDate encoding="w3cdtf">2023-10-27</recordCreationDate>
         <recordChangeDate encoding="w3cdtf">2026-06-27</recordChangeDate>
         <recordIdentifier source="DGPO">GOVPUB-C13-99071e5a8a81d82057f89709c1069c89</recordIdentifier>
         <recordOrigin>machine generated</recordOrigin>
         <languageOfCataloging>
              <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    <accessCondition type="GPO scope determination">fdlp</accessCondition>
    <extension>
         <docClass>C13</docClass>
         <accessId>GOVPUB-C13-99071e5a8a81d82057f89709c1069c89</accessId>
         <uniqueId>99071e5a8a81d82057f89709c1069c89</uniqueId>
         <ACCode>GOVPUB</ACCode>
         <fedPubName>NIST Interagency or Internal Reports</fedPubName>
         <field name="Note">NOTE: THE “DATE ISSUED” ABOVE MAY DEFAULT TO JANUARY 1ST OF A GIVEN YEAR. TO THE VIEW THE MOST ACCURATE DATE OF ISSUE, REVIEW THE TITLE PAGE OF THE PUBLICATION.</field>
         <description>Interim or final reports on work performed by NIST for outside sponsors (both government and non-government). May also report results of NIST projects of transitory or limited interest, including those that will be published subsequently in more comprehensive form.</description>
         <agency abbrev="NIST">National Institute of Standards and Technology</agency>
         <resultsLineTwoText>Commerce Department. National Institute of Standards and Technology. 2022</resultsLineTwoText>
         <dateIssued>2022-02-10</dateIssued>
    </extension>
    <location>
         <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89</url>
         <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89/pdf/GOVPUB-C13-99071e5a8a81d82057f89709c1069c89.pdf</url>
    </location>
    <titleInfo>
         <title>Prioritizing Cybersecurity Risk for Enterprise Risk Management</title>
    </titleInfo>
    <subject>
         <topic>Computer security</topic>
         <topic>Cybersecurity risk management</topic>
         <topic>Cybersecurity risk measurement</topic>
         <topic>Cybersecurity risk register (CSRR)</topic>
         <topic>Enterprise risk management (ERM)</topic>
         <topic>Key performance indicator (KPI)</topic>
         <topic>Key risk indicator (KRI)</topic>
         <topic>Risk acceptance</topic>
         <topic>Risk aggregation</topic>
         <topic>Risk avoidance</topic>
         <topic>Risk conditioning</topic>
         <topic>Risk management</topic>
         <topic>Risk mitigation</topic>
         <topic>Risk optimization</topic>
         <topic>Risk prioritization</topic>
         <topic>Risk response</topic>
         <topic>Risk sharing</topic>
         <topic>Risk transfer</topic>
    </subject>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
         <role>
              <roleTerm authority="marcrelator" type="text">creator</roleTerm>
        </role>
    </name>
    <name type="personal">
         <namePart>Quinn, Stephen.</namePart>
    </name>
    <name type="personal">
         <namePart>Ivy, Nahla.</namePart>
    </name>
    <name type="personal">
         <namePart>Barrett, Matthew.</namePart>
    </name>
    <name type="personal">
         <namePart>Witte, Greg.</namePart>
    </name>
    <name type="personal">
         <namePart>Gardner, R. K.</namePart>
    </name>
    <name type="corporate">
         <namePart>National Institute of Standards and Technology (U.S.)</namePart>
         <namePart>Material Measurement Laboratory</namePart>
    </name>
    <originInfo>
         <place>
              <placeTerm authority="marccountry" type="code">mdu</placeTerm>
        </place>
         <publisher>U.S. Dept. of Commerce, National Institute of Standards and Technology</publisher>
         <dateIssued>2022-02-10.</dateIssued>
         <issuance>monographic</issuance>
    </originInfo>
    <physicalDescription>
         <extent>1 online resource (45 pages) : illustrations (color)</extent>
    </physicalDescription>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">technical report</genre>
    <language>
         <languageTerm authority="iso639-2b" type="code">eng</languageTerm>
    </language>
    <abstract>This document is the second in a series that supplements NIST Interagency/Internal Report (NISTIR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional detail regarding the enterprise application of cybersecurity risk information; the previous document, NISTIR 8286A, provided detail regarding stakeholder risk guidance and risk identification and analysis. This second publication describes the need for determining the priorities of each of those risks in light of their potential impact on enterprise objectives, as well as options for properly treating that risk. This report describes how risk priorities and risk response information are added to the cybersecurity risk register (CSRR) in support of an overall enterprise risk register. Information about the selection of and projected cost of risk response will be used to maintain a composite view of cybersecurity risks throughout the enterprise, which may be used to confirm and, if necessary, adjust risk strategy to ensure mission success.</abstract>
    <note type="statement of responsibility">Stephen Quinn; Nahla Ivy; Matthew Barrett; Greg Witte; R. K. Gardner.</note>
    <note>February 2022.</note>
    <note>Title from PDF title page (viewed January 4, 2023).</note>
    <note type="bibliography">Includes bibliographical references.</note>
    <note type="venue">Approved by the NIST Editorial Review Board on 2022-09-20</note>
    <note type="system details">Mode of access: World Wide Web.</note>
    <note type="system details">Systems requirements: Adobe Acrobat PDF reader.</note>
    <subject authority="lcsh">
         <topic>Computer security</topic>
    </subject>
    <subject authority="lcsh">
         <topic>Risk management</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk management</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk measurement</topic>
    </subject>
    <subject>
         <topic>Cybersecurity risk register (CSRR)</topic>
    </subject>
    <subject>
         <topic>Enterprise risk management (ERM)</topic>
    </subject>
    <subject>
         <topic>Key performance indicator (KPI)</topic>
    </subject>
    <subject>
         <topic>Key risk indicator (KRI)</topic>
    </subject>
    <subject>
         <topic>Risk acceptance</topic>
    </subject>
    <subject>
         <topic>Risk aggregation</topic>
    </subject>
    <subject>
         <topic>Risk avoidance</topic>
    </subject>
    <subject>
         <topic>Risk conditioning</topic>
    </subject>
    <subject>
         <topic>Risk mitigation</topic>
    </subject>
    <subject>
         <topic>Risk optimization</topic>
    </subject>
    <subject>
         <topic>Risk prioritization</topic>
    </subject>
    <subject>
         <topic>Risk response</topic>
    </subject>
    <subject>
         <topic>Risk sharing</topic>
    </subject>
    <subject>
         <topic>Risk transfer</topic>
    </subject>
    <relatedItem type="series">
         <titleInfo>
              <title>NISTIR; NIST IR; NIST interagency report; NIST internal report; 8286B</title>
        </titleInfo>
    </relatedItem>
    <location>
         <url displayLabel="electronic resource" usage="primary display">https://doi.org/10.6028/NIST.IR.8286B</url>
    </location>
    <titleInfo type="alternative">
         <title>Prioritizing cybersecurity risk for enterprise risk management</title>
    </titleInfo>
    <extension>
         <searchTitle>
              <title>Prioritizing cybersecurity risk for enterprise risk management</title>
        </searchTitle>
    </extension>
</mods>