Conduct risk assessments at the three tiers defined in NIST SP 800-30 Rev 1 Section 2.3 and aligned with NIST SP 800-39 governance tiers. Tier 1 Organisational Risk Assessment evaluates strategic risks (mission impact, regulatory exposure, supply chain risk, geopolitical risk) and informs the risk management strategy. Tier 2 Mission and Business Process Risk Assessment evaluates risks to specific mission and business functions and informs enterprise architecture and information protection decisions. Tier 3 Information System Risk Assessment evaluates risks to specific information systems and supports the categorisation, control selection, and authorisation activities of the NIST RMF. Document scope, assumptions, constraints, risk tolerance, and stakeholder list per tier in the risk assessment plan before executing.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 70 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders