NIST SP 800-39
Three-Tier Risk Management Hierarchy

NIST SP 800-39 NISTSP39-1: Risk Management Strategy and Three-Tier Hierarchy (Tier 1, 2, 3)

Establish an organisation-wide risk management strategy per NIST SP 800-39 Chapter 2 (Fundamentals) covering the three-tier hierarchy (Tier 1 Organisation + Tier 2 Mission/Business Process + Tier 3 Information System) and Chapter 3 Section 3.1 (Frame Risk). The strategy must define purpose + scope + assumptions + constraints + risk tolerance + risk priorities + risk-to-be-shared-across-tiers, all aggregated upward and propagated downward across the three tiers. Tier 1 governs organisational risk decisions (risk appetite + budget + executive accountability + Risk Executive Function). Tier 2 governs mission and business process risk (enterprise architecture + segment architecture + protection priorities). Tier 3 governs information system risk (system categorisation + control selection + authorisation decisions per NIST SP 800-37). The strategy document must name the Risk Executive Function (Tier 1) + Information Security Architect (Tier 2) + Authorising Official / System Owner (Tier 3) and define the communication paths between tiers.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.