Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8286A Rev. 1

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

Date Published: December 2025

Supersedes: IR 8286A (11/12/2021)

Author(s)

Stephen Quinn (NIST), Nahla Ivy (NIST), Matthew Barrett (CyberESI Consulting Group), Larry Feldman (Huntington Ingalls Industries), R. Gardner (New World Technology Partners), Gregory Witte (Palydin LLC)

Abstract

Keywords

cyber risk management; cybersecurity risk management; cybersecurity risk measurement; cybersecurity risk register; enterprise risk management (ERM); enterprise risk profile
Control Families

None selected