NIST SP 800-53 Rev 5
PM - Program Management

NIST SP 800-53 Rev 5 NIST800-PM-9: PM-9 Risk Management Strategy

a. Develops a comprehensive strategy to manage: 1. Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and 2. Privacy risk to individuals resulting from the authorized processing of personally identifiable information; b. Implement the risk management strategy consistently across the organization; and c. Review and update the risk management strategy [Assignment: organization-defined frequency] or as required, to address organizational changes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 61 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-05 Risk Management Strategy
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P28 Minimum Contents of the Risk Appetite Statement
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

ISO/IEC 42001:2023 · 7 controls

  • 4.1 Understanding the organization and its context
  • 5.2 AI policy
  • 6.1 Actions to address risks and opportunities
  • 6.1.2 AI risk assessment
  • 6.1.3 AI risk treatment
  • A.3 Internal organization
  • A.9.3 Objectives for responsible use of AI system

ISO 22301:2019 · 5 controls

  • 4.1 Understanding the organization and its context
  • 6.1 Actions to address risks and opportunities
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 8.3.1 General

ISO 27701:2019 · 5 controls

  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 7.2.5 Privacy impact assessment

SOC 2 · 5 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • CPS230-P18 Integration with the Risk Management Framework and Recovery Planning

ISO 27001:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.31 Legal, statutory, regulatory and contractual requirements

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.4 Management responsibilities

NIST SP 800-161 Rev 1 · 2 controls

  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

C5 (Germany) · 1 control

  • CFTC-SS-2 Enterprise Risk Management and Governance Category

DORA · 1 control

EU AI Act · 1 control

HIPAA Security Rule · 1 control

NIS2 Directive · 1 control

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure

NIST SP 800-172 · 1 control

  • 3.11.1e Threat-Aware Risk Assessment

PCI DSS 4.0 · 1 control

  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PM - Program Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PM-9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.