NIST SP 800-30 NISTSP30-8: Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF
Maintain the risk assessment per NIST SP 800-30 Rev 1 Section 3.3 Step 8 (Maintaining the Risk Assessment) and integrate with the NIST Risk Management Framework (SP 800-37) and continuous monitoring (SP 800-137). Maintenance must (a) trigger updates on significant change (system change, environment change, threat change, control failure, incident), (b) refresh annually at minimum even without trigger, (c) update the risk register on each control implementation, change, or failure, (d) feed risk assessment outputs into RMF Authorize step (information needed for authorising official ATO decision), (e) align with continuous monitoring strategy (NIST SP 800-137) so monitoring evidence updates assessment inputs automatically where possible. Documentation retention must support audit readiness with chain-of-custody from threat intelligence + vulnerability scan + control test through to risk register entry through to authorisation decision.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 98 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders