NIST SP 800-39
Risk Executive Function

NIST SP 800-39 NISTSP39-6: Risk Executive Function and Cross-Tier Communication

Operate the Risk Executive Function per NIST SP 800-39 Section 2.3 (Risk Management Roles and Responsibilities) and Appendix D (Risk Management Roles). The Risk Executive Function is a senior position (or formally-constituted group) that (a) develops a holistic view of risk to organisational operations and assets + individuals + other organisations + the Nation, (b) ensures consistent risk decisions across the enterprise informed by the risk frame, (c) coordinates Tier 1 + Tier 2 + Tier 3 risk activities, (d) manages risk-related information sharing inside and outside the organisation, (e) provides oversight for risk management activities carried out by mission/business owners and information system owners, (f) advises authorising officials on enterprise risk implications of authorisation decisions. The Risk Executive Function must have a documented charter + meeting cadence + decision authority + reporting lines + relationship to other risk-related roles (CIO + SAISO + SAPO + Mission Owners).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.