NIST SP 800-30
Risk Management Strategy

NIST SP 800-30 1: Risk Management Strategy and Risk Assessment Programme Establishment

Establish an organisation-wide risk management strategy per NIST SP 800-30 Rev 1 Chapter 2 (Fundamentals) and Chapter 3 (The Process) that (a) defines the purpose, scope, assumptions, constraints, risk tolerance, and priorities for risk assessment, (b) integrates risk assessment with the broader NIST SP 800-39 (Managing Information Security Risk) and NIST RMF (SP 800-37) processes, (c) establishes the risk assessment programme that determines frequency of assessments, triggers for ad-hoc assessments (significant change, incident, new threat intelligence), and management review cadence, (d) defines the three-tier hierarchy (Tier 1 organisation, Tier 2 mission/business process, Tier 3 information system) the organisation will use to scope assessments, (e) names the senior accountable officer (typically Risk Executive Function), the assessment owner per tier, and the maintenance owner. Capture the strategy in an approved risk management policy.

What else in your programme already covers this

This control maps to 83 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

ISO 27005 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 23894:2023 · 3 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO/IEC 27003:2017 · 2 controls

  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • CJIS-19 Supply Chain Risk Management

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components

ISO 22320:2018 · 1 control

ISO 27019 · 1 control

  • ISO27019-21 Supply chain risk management for critical components
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring

NIST SP 1800-32 · 1 control

  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 83 it maps to, and the evidence behind each claim, over MCP and REST.