NIST SP 800-39 NISTSP39-3: Risk Assessing: Organisation, Mission, and System Level Assessments
Execute the Assess step per NIST SP 800-39 Chapter 3 Section 3.2 using NIST SP 800-30 (Risk Assessments) as the supporting methodology. Risk assessment must occur at all three tiers: Tier 1 organisation-wide assessment (strategic risk + supply chain + geopolitical + mission dependency), Tier 2 mission and business process assessment (architecture risk + information protection prioritisation + cross-system dependencies), Tier 3 information system assessment (categorisation + threat events + vulnerabilities + likelihood + impact + system risk). Assessments must use a methodology consistent with the risk frame established in Frame. Outputs feed the Respond step and inform risk-based decisions at each tier. The Assess step at Tier 3 directly feeds the NIST SP 800-37 RMF Prepare (P-3 + P-14) and Authorize (R-2) steps.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 89 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33