Establish an organisation-wide risk management strategy per NIST SP 800-30 Rev 1 Chapter 2 (Fundamentals) and Chapter 3 (The Process) that (a) defines the purpose, scope, assumptions, constraints, risk tolerance, and priorities for risk assessment, (b) integrates risk assessment with the broader NIST SP 800-39 (Managing Information Security Risk) and NIST RMF (SP 800-37) processes, (c) establishes the risk assessment programme that determines frequency of assessments, triggers for ad-hoc assessments (significant change, incident, new threat intelligence), and management review cadence, (d) defines the three-tier hierarchy (Tier 1 organisation, Tier 2 mission/business process, Tier 3 information system) the organisation will use to scope assessments, (e) names the senior accountable officer (typically Risk Executive Function), the assessment owner per tier, and the maintenance owner. Capture the strategy in an approved risk management policy.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 70 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders