Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8286A Rev. 1 (Initial Public Draft)

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

Date Published: February 26, 2025
Comments Due: April 14, 2025
Email Comments to: nistir8286@nist.gov

Author(s)

Stephen Quinn (NIST), Nahla Ivy (NIST), Matthew Barrett (CyberESI Consulting Group), Larry Feldman (Huntington Ingalls Industries), Gregory Witte (Huntington Ingalls Industries), Robert Gardner (New World Technology Partners)

Announcement

The NIST Interagency Report (IR) 8286 series of publications helps practitioners better understand the close relationship between cybersecurity and enterprise risk management (ERM). All five publications in the series have been updated to align more closely with the Cybersecurity Framework (CSF) 2.0 and other updated NIST guidance. The updated series puts greater emphasis on cybersecurity governance to highlight the importance of ensuring cybersecurity capabilities support the broader mission through ERM.

The five updated IR 8286 series publications are:

NOTE: A call for patent claims is included in the front matter of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy  Inclusion of Patents in ITL Publications.

Abstract

Keywords

cybersecurity risk management; cybersecurity risk measurement; cybersecurity risk register; enterprise risk management (ERM); enterprise risk profile
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8286Ar1.ipd
Download URL

Supplemental Material:
None available

Document History:
02/26/25: IR 8286A Rev. 1 (Draft)

Topics

Security and Privacy

risk management, security measurement

Applications

enterprise