NIST SP 800-39
Respond Step (Risk Responding)

NIST SP 800-39 NISTSP39-4: Risk Responding: Identify, Evaluate, Decide, Implement

Execute the Respond step per NIST SP 800-39 Chapter 3 Section 3.3. Risk response includes (a) identifying alternative courses of action for responding to risk (accept + avoid + mitigate + share + transfer per Section 2.5.2), (b) evaluating alternatives against the risk frame and assessment outputs, (c) deciding on the appropriate response considering cost + effectiveness + acceptability + feasibility, (d) implementing the selected response by mapping to controls per NIST SP 800-53 + organisational change + contractual mechanisms + insurance + service-level agreements as appropriate, (e) documenting and communicating risk decisions with rationale to affected stakeholders at each tier. Risk sharing and transfer arrangements (Section 2.5.2.4) must be explicitly evaluated for supply chain risk per NIST SP 800-161 and other sharing relationships.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 70 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • CJIS-19 Supply Chain Risk Management

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring

NIST SP 1800-32 · 1 control

  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • CRM-3 Risk Management Framework

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 70 it maps to, and the evidence behind each claim, over MCP and REST.