NIST SP 800-39
Frame Step (Risk Framing)

NIST SP 800-39 NISTSP39-2: Risk Framing: Risk Frame Components and Trust

Execute the Frame step per NIST SP 800-39 Chapter 3 Section 3.1. Framing produces a risk frame that establishes the context within which risk-based decisions are made. The risk frame must capture (a) risk assumptions about threats, vulnerabilities, impact, likelihood, predisposing conditions and uncertainty, (b) risk constraints (legislative, regulatory, contractual, organisational, financial, operational), (c) risk tolerance for each risk category (mission impact, financial loss, regulatory penalty, reputation, safety), (d) risk priorities and trade-offs across competing objectives. Framing must also establish trust relationships and information sharing arrangements per Section 2.3.4 (validated trust + direct historical trust + mediated trust + mandated trust) with mission partners, supply chain, service providers, customers, and external information sources. Output: documented risk frame approved at executive level, propagated to Tier 2 and Tier 3.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.