Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8286C Rev. 1

Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

Date Published: December 2025

Supersedes: IR 8286C (03/06/2024)

Author(s)

Stephen Quinn (NIST), Nahla Ivy (NIST), Matthew Barrett (CyberESI Consulting Group), R. Gardner (New World Technology Partners), Matthew Smith (Seemless Transition LLC), Gregory Witte (Palydin LLC)

Abstract

Keywords

cyber risk management; cybersecurity risk management (CSRM); cybersecurity risk measurement; cybersecurity risk register (CSRR); enterprise risk management (ERM); enterprise risk profile (ERP); enterprise risk register (ERR); key performance indicator (KPI); key risk indicator (KRI); risk prioritization
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8286Cr1
Download URL

Supplemental Material:
See NIST IR 8286r1 Supplemental Material

Publication Parts:
IR 8286 Rev. 1
IR 8286A Rev. 1
IR 8286B
IR 8286D

Document History:
02/26/25: IR 8286C Rev. 1 (Draft)
12/18/25: IR 8286C Rev. 1 (Final)

Topics

Security and Privacy

risk management, security measurement

Applications

enterprise