Date Published: February 26, 2025
Comments Due:
Email Comments to:
Author(s)
Stephen Quinn (NIST), Nahla Ivy (NIST), Matthew Barrett (CyberESI Consulting Group), Robert Gardner (New World Technology Partners), Matthew Smith (Seemless Transition LLC), Gregory Witte (Huntington Ingalls Industries)
Announcement
The NIST Interagency Report (IR) 8286 series of publications helps practitioners better understand the close relationship between cybersecurity and enterprise risk management (ERM). All five publications in the series have been updated to align more closely with the Cybersecurity Framework (CSF) 2.0 and other updated NIST guidance. The updated series puts greater emphasis on cybersecurity governance to highlight the importance of ensuring cybersecurity capabilities support the broader mission through ERM.
The five updated IR 8286 series publications are:
- NIST IR 8286r1 (Revision 1) initial public draft (ipd), Integrating Cybersecurity and Enterprise Risk Management (ERM) — This document is intended to help individual organizations within an enterprise improve their cybersecurity risk information, which they provide as inputs to their enterprise’s ERM processes through communications and risk information sharing.
- NIST IR 8286Ar1 ipd, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management — This document details the context, scenario identification, and analysis of the likelihood and impacts of cybersecurity risk.
- NIST IR 8286B-upd1 (Update 1), Prioritizing Cybersecurity Risk for Enterprise Risk Management — This document describes ways to apply risk analysis to help prioritize cybersecurity risk, evaluate and select appropriate risk responses, and communicate risk activities as part of an enterprise cybersecurity risk management strategy.
- NIST IR 8286Cr1 ipd, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight — This document describes processes for aggregating information from CSRM activities throughout the enterprise.
- NIST IR 8286D-upd1, Using Business Impact Analysis to Inform Risk Prioritization and Response — This document describes considerations for documenting and analyzing business impacts that result in a full or partial loss of the confidentiality, integrity, or availability of a mission-essential resource.
NOTE: A call for patent claims is included in the front matter of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.
This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and 8286B, provide details regarding stakeholder risk direction and methods for assessing and managing cybersecurity risk in light of enterprise objectives. This report, IR 8286C, describes how information recorded in cybersecurity risk registers (CSRRs) may be integrated as part of a holistic approach to ensuring that risks to information and technology are properly considered for the enterprise risk portfolio. This cohesive understanding supports an enterprise risk register and enterprise risk profile that, in turn, support the achievement of enterprise objectives.
This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and...
See full abstract
This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and 8286B, provide details regarding stakeholder risk direction and methods for assessing and managing cybersecurity risk in light of enterprise objectives. This report, IR 8286C, describes how information recorded in cybersecurity risk registers (CSRRs) may be integrated as part of a holistic approach to ensuring that risks to information and technology are properly considered for the enterprise risk portfolio. This cohesive understanding supports an enterprise risk register and enterprise risk profile that, in turn, support the achievement of enterprise objectives.
Hide full abstract
Keywords
cybersecurity risk management (CSRM); cybersecurity risk measurement; cybersecurity risk register (CSRR); enterprise risk management (ERM); enterprise risk profile (ERP); enterprise risk register (ERR); key performance indicator (KPI); key risk indicator (KRI); risk prioritization
Control Families
None selected